This will be the death of Nostr. The only way I can to spot imposter accounts is because my client has a “nifty” algo to track “similar names” and such.

WoT implementations on Nostr should NOT be so haphazard, specific to each client or relay. Nostr needs a standard by which users can be IN CONTROL of the filters they use. The ones that work will be shared and used more.

This is ridiculous.

nostr:npub1a2cww4kn9wqte4ry70vyfwqyqvpswksna27rtxd8vty6c74era8sdcw83a

Reply to this note

Please Login to reply.

Discussion

It's a bad joke 👀

No. Actual phishing.

what's wrong?

Imposter accounts on nostr. Rampant.

ok, everyone can have the same username

Nix kind0. Npubs only. Problem solved. Lol.

The above screenshots are from nostr:npub1n0stur7q092gyverzc2wfc00e8egkrdnnqq3alhv7p072u89m5es5mk6h0 client, which has a simple “similar name and pfp” detection algo.

Heres how nostr:npub1pu3vqm4vzqpxsnhuc684dp2qaq6z69sf65yte4p39spcucv5lzmqswtfch warns of the same post, using “flagged content” feature.

Not only are these completely different types of filter for the same use case, but AS A USER, I dont have any control over which filter use.

Nostr needs a WoT standard!

Which is the impostor? FoF seems not terribly haphazard to me.

I tagged Lyn in a post recently with the @ name that I follow which is the real Lyn but it linked the tag to an imposter. Not sure wtf is going on. Realistically I’d pay to follow Lyn and some other accounts with a one time sat fee. Not sure if that would fix this issue

That's not great, what client was it?

I mean was this snort, coracle, amethyst, etc?

Does it matter?

Damus shows a purple icon next to the person you follow and should present that first. Although the follow sorting is only in TestFlight atm, maybe thats the issue.

I think when I typed the full tag, I didn’t select which Lyn account. I just typed it and posted. And it defaulted to an imposter rather than the real Lyn. This means you have to pay attention to select the correct account any time you tag instead of just typing the correct tag since it could link to an imposter.

Maybe y’all could offer considered feedback on the solution I have proposed…?

- Take the weight OFF from each client to solve the “content and trust ranking” problem in their OWN.

- Retain the free market of ideas that currently exists with each client designing their own algos.

- BUT BETTER when users can share amongst themselves, and inter mix these algos and filters to discover the best results for their use case.

nostr:note1aej3d6n9twm7y8vgvq8dq5aahhy0wkc900xpdh8n8a7rsxm0msdspyrf85

This needs to get better.

👆🏼THIS

Whatever filter 21 has access to (in the client) was NOT enough to keep the bot from INJECTING itself INTO THE POST.

If 21 had trusted friends with BETTER content filters, (including the 1 say fee idea?) this could be easily remedied by sharing it.

Nostr needs a way to share (and discover the best) content filters and trust rankings!!

just check the npub. can also just look at follow counts and content.

Dude. Who TF checks npubs?

This is not an intellectual problem. It is a real world user problem. Nostr is dead already.

umm, i do, and I hope everyone does

that's literally the point of signing and having private and public keypairs, lol.

the key can't be spoofed on the relays. they can spoof account names, nip05 maybe, avatars, and more. but if you know the npub, nonworries.

We all know this. But the real world usage (your and mine prolly also) is different. We need to solve for real world.

What is the issue?

On X, you post something and may get a reply from elon(or whoever), you look at the profile, yes? In that case, the username would be elonmsk or a letter off or a number.

Seems pretty simple. Perhaps a dB of usernames that clients could compare, but it'd never been an issue for me. I've been followed by fake Lyn accounts, I take a look, fake. Blocked or muted or no action. Done.

Everything in your comment requires a central auth DB or a user who is dedicated to “not be phished”.

Nostr will grow. People will be followed by (and follow back) bots and bad actors. Spam and phishing attempts will be shared and reposted.

There is no central auth in Nostr. Our only defense is Webs of Trust between friends and friends of friends. But Nostr only has ad-hoc implementations to establish webs of trust.

Nostr needs better tools. And by this I mean, a free market of tools (content filters and trust rankings) whereby the best ones will emerge.

If someone can take the time to check a profile or other means, I hope they get scammed. Lazy people have ruined this earth enough.

Ok.

No, it will not. It’s a problem to be solved.

Feel free to submit a PR.

I’m making a bit of noise before i submit. I’d rather get early feedback from ALL of nostr than only from the 5 or 6 ppl who review NIP pull requests.

Your considered feedback is appreciated.

nostr:note1aej3d6n9twm7y8vgvq8dq5aahhy0wkc900xpdh8n8a7rsxm0msdspyrf85

Also… it will.

AS nostr adoption grows, bots and bad actors will come in waves to phish the plentiful and open waters of nostr network. What’s to stop them? People will leave if their feed is unmanageable.

nostr:note1et4mu9mvhd5pyuul94hpk48h2xjvf5t3e9v3cfqkvnv2uwck8ngsa4f86j

In the words of Satoshi, if you don’t get it…