ExploreTrendingAnalytics
Nostr Archives
ExploreTrendingAnalytics
Hanshan266d ago
he apparently missed that they have a RSA key hardcoded into the client now so... πŸ˜•
πŸ’¬ 1 replies

Thread context

Root: e554bd94cda8…

Replying to: 1709395291c8…

Replies (1)

Dan Gould266d ago
Seems like clients don’t verify that signatures actually come from that hardcoded key (which they are definitely able to do). Until that is done clients are still vulnerable to a coordinator tagging attack.
0000 sats