What is Nostr?
calle 👁️⚡👁️
npub12rv…85vg
2024-02-12 11:58:32
in reply to nevent1q…4e63

calle 👁️⚡👁️ on Nostr: I see the risk in this and I think it also applies to other NIP07 applications that ...

I see the risk in this and I think it also applies to other NIP07 applications that can get signatures on notes from the extensions (they could publish fake notes signed by you).

There seems to be no other way than to show the user what they are signing. I wish Alby (npub1get…0nfm) had a dedicated way of showing details of the ecash that is being signed. Maybe one day?

Definitely needs trust in the application that is requesting these signatures. What's true for signing messages is also true for signing transactions.
Author Public Key
npub12rv5lskctqxxs2c8rf2zlzc7xx3qpvzs3w4etgemauy9thegr43sf485vg