The section quoted below is poorly worded. The feature was improperly designed/deployed if it exposed the email in the browser that the password reset was sent to. But thank you for the quick disclosure.

Perhaps use this as a teaching moment on #nostr responsible disclosure of #security issues from the community. Incentivize it with a Bitcoin bug bounty in the future.

Alby is still a fundamentally valuable service for me personally.

" ... publicly exposed by their owner.

Password request emails also have been requested for lightning addresses which falsely exposed the user's email address. This had been a feature deployed to help users keep easy access to their accounts. But as many users post their lightning address on profiles like nostr this should not be exposed and a fix has been deployed immediately. Generally there should be no way to display a user's email address. We have failed here. About 5500 password reset emails had been requested by the attacker.

nostr:nevent1qqswh5upmuma0h89vdnh7pnk6ap637xg0mtt0k32hwaxrxm98vuv28cpz4mhxue69uhhyetvv9ujuerpd46hxtnfduhsygzx2l0739jmazvq4yc8908mtev6v5fygpkmp7qey90w0zay0y6t8cpsgqqqqqqsdl99uv

Reply to this note

Please Login to reply.

Discussion

Hi sorry to bother you guys!! Please Check out our geyser. it’s for our son πŸ™πŸ» thanks so much!! Have a blessed day.

nostr:nevent1qqsv5rd33pl0rk0yqs495r2xct9m8a5uar0ktn6yf8vlrv0dam0eg7qpz3mhxue69uhhyetvv9ujuerpd46hxtnfdu86egfz