someone ping Derek thereβs a Carla impersonator using nostr plebs NIP-05 to try to scam plebs nostr:note1yn0xlxrmf9kkmq8e7kpn84za3ry6rlnutmfqmde6urcfhkhhdzxqx7esgc
Discussion
yeah i got a dm too
Can you tag him? Damus wonβt let me ):
Hey nostr:npub18ams6ewn5aj2n3wt2qawzglx9mr4nzksxhvrdc4gzrecw7n5tvjqctp424 just a heads up tag for sleepy
Just got a dm from him, it appears itβs just the username, Carla owns the real oneβ¦ but it still threw me off, as well as that banner π€£
clients should label these as βspamβ or βscamβ
I don't think there's any effective way of determining it's spam. Maybe WoT?
if itβs using a NIP-05 that belongs to another pleb thatβs the owner, should be easy.
One nsec/npub owns it
any other that adds it to their profile as a username or whatever would be labeled spam
Oh yeah, trying to use a nip05 someone else has registered won't validate, at least it shouldn't (the client should verify it against the users' pubkey used in the app). Adding a spam label would add another level of awareness π
But this won't stop them from registering a similar nip05, which is what I was referring to when I mentioned address as a service websites.
nostr:npub18m76awca3y37hkvuneavuw6pjj4525fw90necxmadrvjg0sdy6qsngq955 tagging broken per usual /: 
Hmmm nostr:npub1zafcms4xya5ap9zr7xxr0jlrtrattwlesytn2s42030lzu0dwlzqpd26k5 I havenβt had this happen
happens to me quite often https://v.nostr.build/c6S9LMLiOYbKoETi.mp4
These nostr address as a service sites are useful, but perhaps it should be by request only. Otherwise it's very easy for scammers to get a nip05 anyway.
I also got the dm. But this profile is not nip5 verified, it shows a disclaimer in the cover image telling to check nip5, therefore shows that the profile is a malicious impersonation. Some plebs may fall for that, unfortunately
What client are you using ? I didnβt get a disclaimer
I'm using amethyst. It shows that, but the profile is not really nip5 verified were it should appear. 
Oh thatβs the banner image
would be nice if the pages that used nip-05s in their usernames that belong to another owner should have a disclaimer saying itβs a βscamβ or βspamβ
Yes, it's the banner image. But do you see the nostrplebs verified checkmark on the fake profile?
This is why we canβt use nip5 for any kind of verification
this is because they set their username field to βCARLA@nostrplebs.comβ and not NIP-05
this confusingly leads to it appearing like a NIP-05 even though it is not