Avatar
Nicolas Burtey
2bda4f03446bc1c6ff00594e350a1e7ec57fb9cdc4a7b52694223d56ce0599e9

To bbw

seems we have still some debugging to do

Replying to Avatar Luxas

Let's talk #phishing on #nostr

The art of the catch is in being as deceitful as possible and mimicking something familiar that your target takes the bait.

Nostr clients (at least the web ones) allow you to login to someone else's account as read-only mode.

You can see their notifications and even see who has messaged them. It's even possible to know who the target replied back to, as standard message bubbles give it away.

https://imgur.com/a/uraDw64

Of course, the contents of messages cannot be read, as they're encrypted.

But, if you're farming for victims to pwn, and you see they DM'd an "influencer", it'd be easy to create a clone account of the influencer, register a near-match domain, get it NIP-05'd and then send your targets a DM.

I'd venture to guess not many (at least not many of the technologically inept) would take the time to validate the pubkey.

It would be great if there could be some sort of secondary auth for viewing notifications/messages when in read-only mode. Not the privkey, but a password or something else only the account owner would know.

This way, the account can remain in read-only mode without the ability to sign messages, but the things that should remain private, stay private and less susceptible to being used as phish bait.

As the saying goes, "trust, but verify". Stay vigilant #nostriches and ensure whoever DMs or replies to you is really who you think it is. There will always be malicious actors, but you can prep to combat them!

Inretesting how the fact metadata on PM between are people are visible for everyone make Nostr a platform where phishing will be even be more effective than on Twitter

Does PM even make sense if there is no p2p component?

Zap from #[0] should really work now 😂

Give it a try!

Should work now. We didn’t had the pubkey in lowercase

Only BBW <> BBW are not yet reported

You don’t have any lightning address to your profile

nip-57 should be live from

#[0]

anyone want to try and give feedback?

Doing a micro-hackathon to integrate nip-57 into the #[0]

If you want to join the effort, join our room link: https://us02web.zoom.us/j/88107615194?pwd=U2Z5VHhXMkNqcnplNEp2MzhmMnVrQT09

It'll be fun!

Does Iris support nip57?

I added the relay on the list on Damus. How am I supposed to pay? I’m not prompted for anything automatically

Is it a good idea to run a relay on a raspberry pi?

Isn’t this ressources intensive?

Any benchmark yet showing the consumption of a relay given xxx users connected to it?