taking a new tack on NIP-42

https://github.com/nostr-protocol/nips/issues/1120

i know what is in principle required for a proxy-safe authentication protocol to enable a client to proxy through another relay to auth to a second relay that requires authentication, this is the main use case, and the purpose of it is actually, ironically, reducing traffic for the user, since this would allow them to auth to multiple relays and thus would then open the door to a request message that bounces from the proxy relay

but you can't do it without first enabling a single path proxy relaying scenario

i am trying to drum up support from clients to support proper authentication because without client authentication the promise of a self-funded network is dead in the water, how can you meter access to data without this!

by adding an ephemeral encryption key it prevents the middleman from seeing the challenge or the response which kills the MITM vector dead

Reply to this note

Please Login to reply.

Discussion

No replies yet.