mleku on Nostr: this prompted a question in my mind just now, and an answer came how is it that ...
this prompted a question in my mind just now, and an answer came
how is it that static cryptographic identities seem to be strong in nostr
partly, because if someone were to actually post events with the key they managed to steal from you
you'd see it the next moment you open your nostr client and it displays the event kind they posted with that key
right now kind 1's are definitely a no-go for an nsec thief
because many clients are retarded about DMs though, and auth, they might exploit their achievement by riding your reputation with their stolen booty
but at the same time, the conventions in the protocol are so leaky, that it's possible they would be detected by someone who would mention you in a kind 1 that you seem to be sending spam
this is an interesting thing, and may well be why nostr's DAU is slow to grow
most people think it's insecure, on the face of it
those who use it, never have a problem because it's so easy to get noticed doing bad thing
most of the relays don't actually keep logs and nobody really talks about that possibility, but it exists, and the bad guys might well consider it best to only use your nsec to read your encrypted events, and not alert you they have it by posting
how is it that static cryptographic identities seem to be strong in nostr
partly, because if someone were to actually post events with the key they managed to steal from you
you'd see it the next moment you open your nostr client and it displays the event kind they posted with that key
right now kind 1's are definitely a no-go for an nsec thief
because many clients are retarded about DMs though, and auth, they might exploit their achievement by riding your reputation with their stolen booty
but at the same time, the conventions in the protocol are so leaky, that it's possible they would be detected by someone who would mention you in a kind 1 that you seem to be sending spam
this is an interesting thing, and may well be why nostr's DAU is slow to grow
most people think it's insecure, on the face of it
those who use it, never have a problem because it's so easy to get noticed doing bad thing
most of the relays don't actually keep logs and nobody really talks about that possibility, but it exists, and the bad guys might well consider it best to only use your nsec to read your encrypted events, and not alert you they have it by posting
quoting nevent1q…narjI have a question for you, I know you are real, but is this you posting? Haha