The slides for a recent Black Hat talk on vulnerability in many nostr clients is up.

https://i.blackhat.com/BH-USA-25/Presentations/USA-25-Kimura-Not-Sealed-Practical-Attacks-on-Nostr.pdf

I haven't had a chance to read through it completely yet but seems like most, if not all, of what they lay out are known issues and things we've all been working to fix for a while now. 🤷‍♂️

Reply to this note

Please Login to reply.

Discussion

I added a placeholder for automating e.g. event validation tests across apps

https://github.com/nostrability/nostrability/issues/227

"Verify signatures kids"? This seems like a nothing burger. Flaws in specific clients, but not the protocol itself

Black hat and def con are captured. Pure fud