i tried to get a modification done to NIP-42 that removed the requirement of a DNS - yes DNS based relay address from the response message

and of all people the guy who tried to write a relay proxy got very het up about me proposing this as though i was making the protocol insecure

actually, it doesn't make it insecure, it just does slightly weaken the man in the middle attack protection, in exchange for allowing a man in the middle (proxy) to act on your behalf

part of the problem is that the relay needs to be sending the challenge encrypted

so i'm going to pursue this avenue to get NIP-42 actually working securely enough that it gets adopted, as it's key to my strategy towards getting actual PAID RELAYS working as a general pattern and minimising the free relay use case, as is the case right now

#devstr

help is welcome, if anyone has thoughts

Reply to this note

Please Login to reply.

Discussion

No replies yet.