What is Nostr?
Daniel Gultsch /
npub1ypg…pqu5
2023-10-23 15:14:09

Daniel Gultsch on Nostr: Two more things to note before we roll out channel binding: · It’s not ...

Two more things to note before we roll out channel binding:

· It’s not unreasonable to assume that future attacks will use stolen certificates. Therefore 'endpoint' is an inferior channel binding method and servers that have other methods available (unique or exporter) should not be offering 'endpoint' at all to avoid down grade attacks.¹
· Channel binding relies on the password staying secret; Make sure you are not reusing passwords across services.

¹: I realize XEP-0440 might imply otherwise
Author Public Key
npub1ypgz3qavuftxd7jduyhldlqpk2n2v4xcnc5rgtk4y0paycky5t7qfjpqu5