Explore
Trending
Analytics
Nostr Archives
Explore
Trending
Analytics
Dan Gould
266d ago
Seems like clients don’t verify that signatures actually come from that hardcoded key (which they are definitely able to do). Until that is done clients are still vulnerable to a coordinator tagging attack.
💬 1 replies
❤️
0
Reactions
🔁
0
Reposts
⚡
0
Zaps
Thread context
Root:
e554bd94cda8…
Replying to:
3a44b213177a…
Replies (1)
Hanshan
266d ago
have you also verified about the signatures or are you just taking floppy's word for it?
0
0
0
0 sats