It’s not taking my nsec πŸ€”

Reply to this note

Please Login to reply.

Discussion

use extension to login on desktop πŸ‘€

it's not good nsec hygiΓ«ne to put your nsec into websites manually

Cyber hygiene ✍🏻

πŸ§˜πŸΌβ€β™€οΈ

Ooopsss

this is why i had to generate a new keypair aka account

i put my nsec in Anigma last year which leaked keys we found out later 😬

Uh… they leaked? How/where/etc, please?

idk the details exactly but it was compromised

i asked many times but no one had given me an answer yet to how this happened and what other clients now do to prevent it

XSS vulnerability

thank you πŸ₯³

Ugh. Thanks.

β€œCross-site scripting is a type of security vulnerability that can be found in some web applications. XSS attacks enable attackers to inject client-side scripts into web pages viewed by other users. A cross-site scripting vulnerability may be used by attackers to bypass access controls such as the same-origin policy.” I understood nothing, is it possible this could still happen to me putting my nsec into these new clients ??

would like to know too.. and if it's also something that can happen with mobile apps

i see it can be done with phishing links

and can ppl do this with img urls too? they automatically open since we can see them, right?

Yeah also is there a browser that would protect from such attacks ?

Definitely not in a mobile app AFAIK. It’s a browser problem. Image files a different. It’s simply a file. There’s no code being run unlike a web page.

luckily we still early now so mifht want to create a backup account and ask people to follow it once in a while so you bave have something to fall back to when shit hits the fan fr