Question: What if a user of a mint that requires authentication sends ecash to another user who's not part of the mint?

Answer: You will be able to send the ecash together with an access token that allows the receiver to withdraw the ecash to their Lightning wallet – but that user will not be able to "join" the mint.

Reply to this note

Please Login to reply.

Discussion

Why would the mint allow that/issue such an access token??

It would bypass their very own security rule, in that only users who signed up for their mint should be able to use that mint.

it can't be prevented

Sure.

- Short lived tokens

- ban auth attempts from the same token from different IP

+2FA

Seems complicated, where does this person get the access token?

Why not make it public to trade a nut for a Lightning invoice but not for a nut swap?

Or if for a nut swap, then only for a nut that is marked as withdrawal only. Also one that is clear for any reciever to identify that it is a withdraw only nut offline (so they know they can't prevent a double spend and so they shouldn't accept it)