solo on Nostr: cohost doesn't sanitize their html. the entire website is susceptible to an ...
cohost doesn't sanitize their html.
the entire website is susceptible to an zero-click deanonymization attack.
also forgot to include the link earlier, so here's that:
original post
Published at
2024-03-26 03:30:22Event JSON
{
"id": "0e44ab00d6353084a77120c6db7b4bb358458bf66c677bd63f8049d41726432c",
"pubkey": "974e531a3e97891a46a15f3476faf8d0ad92a09082d73dedb994a8d3592328c6",
"created_at": 1711423822,
"kind": 1,
"tags": [
[
"proxy",
"https://tech.lgbt/users/solonovamax/statuses/112159871646820650",
"activitypub"
]
],
"content": "cohost doesn't sanitize their html.\n\nthe entire website is susceptible to an zero-click deanonymization attack.\n\nalso forgot to include the link earlier, so here's that:\noriginal post\n\nhttps://media.tech.lgbt/media_attachments/files/112/159/855/612/155/758/original/0ebfd7e654e099a8.png\n\nhttps://media.tech.lgbt/media_attachments/files/112/159/865/944/400/866/original/c75c3794bbf2914a.png",
"sig": "6627b1db3a421c49d6794def75d8563180241a38988184bc7903f2399a1ce2172639249064a74db6121f8b6415947f936dad584b8d0343be7c03f52ed9b11b48"
}