Explore
Trending
Analytics
Nostr Archives
Explore
Trending
Analytics
Hanshan
266d ago
he apparently missed that they have a RSA key hardcoded into the client now so... π
π¬ 1 replies
β€οΈ
0
Reactions
π
0
Reposts
β‘
0
Zaps
Thread context
Root:
e554bd94cda8β¦
Replying to:
1709395291c8β¦
Replies (1)
Dan Gould
266d ago
Seems like clients donβt verify that signatures actually come from that hardcoded key (which they are definitely able to do). Until that is done clients are still vulnerable to a coordinator tagging attack.
0
0
0
0 sats