Global Feed Post Login
Replying to Avatar fiatjaf

There are a dozen of issues with this scammy paper.

The most important is that it only worked on a couple of clients that didn't check signatures. These clients only connected to a static set of semi-trusted relays and changing the relays they connected to would require a manual typing operation from the user.

For the attack to work it required victims to manually type the URL of the attacker relay, which makes it completely absurd.

It's like telling someone to visit "verysecretnotscammywebsite.com" and type all their secrets there, then read their secrets because the website leaked them and write a paper claiming that the web is broken.

Avatar
Luxas 2mo ago

How old is the paper? They mention Plebstr client, which hasn't been around for a very long time lol

Reply to this note

Please Login to reply.

Discussion

Avatar
Lady Mae - Growth Teacher 2mo ago

according to the papers the poc was done last 2023 but their metadata says they updated it this Aug 2025

Thread collapsed