Clients should both validate the sha256 of the message and the sig. Anything other than that, you open an attack vector using rogue relays.
It's not cheap! This is the tradeoff of the Nostr architecture.
Clients should both validate the sha256 of the message and the sig. Anything other than that, you open an attack vector using rogue relays.
It's not cheap! This is the tradeoff of the Nostr architecture.
No replies yet.