Replying to Avatar Leo Wandersleb

Oh fuck, why? Now I'm paranoid about all kind of things. So nostr:npub1ye5ptcxfyyxl5vjvdjar2ua3f0hynkjzpx552mu5snj3qmx5pzjscpknpr's NoStrudel does not check my follows list's signature? Please tell me this is not true!

Why would it matter? Say I use 12 relays. One of them is compromised. Now that relay can serve my client a modified follows list with a newer date than the others and my client will use this over the others. Next time I add a follow, my nsecBunker or whatever secure way of using my keys will even sign off on the modified list. And before I know what's going on I'm zapping a hacker or get scammed by impersonators.

nostr:nevent1qvzqqqqqqypzqlxr9zsgmke2lhuln0nhhml5eq6gnluhjuscyltz3f2z7v4zglqwqqsxpszhf6r3jk7f3swjjvkykty0q9pp4zp4naymjukmv5j2c50vsdgu0md2u

This indeed is a suspicious setting. It implies that signatures are not always checked. Scary.

Reply to this note

Please Login to reply.

Discussion

No replies yet.