What is Nostr?
brito
npub1hfg…7yfm
2024-10-05 18:51:25
in reply to nevent1q…szmu

brito on Nostr: Deterministic builds don't help when you are trusting whatever binaries for the ...

Deterministic builds don't help when you are trusting whatever binaries for the client are available on the Play Store (even easier there to target specific users). There is no need to verify relays on our end because the E2EE encrypted messages are not possible to break unless the client on our side is cooperating.

That is why it is VERY dangerous to use the client and server provided by the same supplier.

At NOSTR there is no such thing since servers and clients are plenty from different suppliers. Attention that it isn't impossible to simultaneously bribe Amethyst, Primal and so on as attack vectors, but just 100x more difficult than targetting SimpleX because it is a money-thirsty company that provides the ONLY software option both the client and server at the same time.
Author Public Key
npub1hfg3tsmmp7g3u5cw6mzg0n9andehmgel6jug486eppsr0rqx4a3qlp7yfm