Bitcoin Forum

Bitcoin => Bitcoin Discussion => Topic started by: carbonpenguin on May 17, 2011, 06:03:31 PM



Title: The Logistics of Accepting Bitcoin Donations?
Post by: carbonpenguin on May 17, 2011, 06:03:31 PM
I was going to just put an address on my blog, but I remember reading somewhere that doing so is a bad security practice. Is there a simple plug-and-play widget out there that generates random addresses that would be easy to put on a blogspot blog?


Title: Re: The Logistics of Accepting Bitcoin Donations?
Post by: edd on May 17, 2011, 06:10:56 PM
I used the mybitcoin merchant tools to create an encrypted link (see the Tip Jar at the top of the BitBrew (http://bitbrew.net/) site).


Title: Re: The Logistics of Accepting Bitcoin Donations?
Post by: carbonpenguin on May 17, 2011, 06:19:31 PM
Nice - I'll give that a try.


Title: Re: The Logistics of Accepting Bitcoin Donations?
Post by: bittersweet on May 17, 2011, 06:22:24 PM
I was going to just put an address on my blog, but I remember reading somewhere that doing so is a bad security practice.

For donations? It's not. Unless you don't want other people to know how much donations you received.
If you use a single address for all donations it can be easily checked.

If you sell something it gets more complicated because you must be sure who paid you.


Title: Re: The Logistics of Accepting Bitcoin Donations?
Post by: carbonpenguin on May 17, 2011, 06:36:46 PM
I'd read somewhere it was vulnerable to a "man-in-the-middle" attack. Not sure what that means, but I figured it'd be good to be careful.


Title: Re: The Logistics of Accepting Bitcoin Donations?
Post by: kiba on May 17, 2011, 06:37:52 PM
I'd read somewhere it was vulnerable to a "man-in-the-middle" attack. Not sure what that means, but I figured it'd be good to be careful.

Well, if somebody can modify your web page without permission, than it is vulnerable to a "man-in-the-middle" attack.


Title: Re: The Logistics of Accepting Bitcoin Donations?
Post by: rezin777 on May 17, 2011, 06:38:48 PM
I'd read somewhere it was vulnerable to a "man-in-the-middle" attack. Not sure what that means, but I figured it'd be good to be careful.

Well, if somebody can modify your web page without permission, than it is vulnerable to a "man-in-the-middle" attack.

Meaning they can change your address to their address and donations that were meant for you will go to them.


Title: Re: The Logistics of Accepting Bitcoin Donations?
Post by: Gavin Andresen on May 18, 2011, 12:44:58 AM
I'd read somewhere it was vulnerable to a "man-in-the-middle" attack. Not sure what that means, but I figured it'd be good to be careful.

To be completely sure you get all the donations you deserve, you should put the donation address on an https:// page.

Otherwise hackers can hijack http: pages if they can insert themselves into the network between you and your web visitors, and replace the donation address on the webpage with their bitcoin address.