Global Feed Post Login
Replying to Avatar Vitor Pamplona

Reminder: NIP-04 DMs have a security flaw.

With significant use (DMs + private zaps + zap payment requests via wallet connect + private lists), an attacker with sufficient hash power can brute force your private key.

Please consider migrating to the new DM with GiftWraps as early as possible.

We also invite all white-hat cryptographers out there to try to break the new system. The sooner we can stress test the design, the better it gets.

Avatar
Melvin Carvalho 2y ago 💬 1

Explain how?

Reply to this note

Please Login to reply.

Discussion

Avatar
Vitor Pamplona 2y ago 💬 10

I have to defer to Paul on this one: https://github.com/nostr-protocol/nips/pull/715#issuecomment-1675301250

Thread collapsed