Wow. Just tested with my nostr:nprofile1qqstu8vf099ljt09m4jvres0dgk8ps2q4wkfjvjp3lhrp3wxxllfg7gpzpmhxue69uhk6mnv9emrqmpwd9hszrmhwden5te0dchx76es9ehhyecym2km9 readable receiving address and it was able to extract my full transaction history.

Testing the invoices and/or readable receiving addresses from nostr:nprofile1qqswe03hyye2jv3msylwkj8cml8d4m9qpc5g0tccrvrrcm86z0kcagg0zjv3w and nostr:nprofile1qqsvn0dkjt80raqrxd470c98n7zrdehmcvj6p5hgw3kyku6zyd8z0fqpz4mhxue69uhk2er9dchxummnw3ezumrpdejqzrthwden5te0dehhxtnvdakquw0j5p both did not reveal that data.

Until this changes I will stop using Wallet of Satoshi. It's a shame, I really like the app.

Reply to this note

Please Login to reply.

Discussion

This doesn't just work for any lightning address, only ones that are using spark internally. (and also seemingly not all of them, no idea why yet)

It's a config option when creating an invoice, WoS could turn it off if they wanted to

Are there any non-obvious reasons not to turn it off?

Saves on fees for spark to spark transfers

Because they can directly settle internally between WoS users without touching lightning at all?

Yeah

Okay, cool. Thanks for jumping in and explaining things, makes sense now. 🙏