Post
Topic
Board Development & Technical Discussion
Re: Why Using SSL's PKI For BIP 70 is a Big Mistake
by
kendo451
on 10/03/2014, 14:58:49 UTC
The point is that HTTPS is flawed in a number of ways, though more political than technical. (He who controls the CA's controls the world.  The CA's charge a shitload of money for certs, but hardly do any verification and refuse to be held liable when they issue a cert to a known phishing site, etc.)

Bitcoin could write its own protocol, or else include the CA Cert root certificates in the clients by default.  Otherwise, as Grigg has pointed out, Bitcoin merchants will find themselves at the mercy of CA's in order to accept Bitcoin payments.  That hands control over a substantial part of the Bitcion network back to the Establishment.

If you don't want to do a better protocol than HTTPS, then at least include the CA Cert root certificates in every client so Bitcoin merchants can use a decentralized CA without paying exorbitant fees for SSL certs.