What is Nostr?
Bashee Von Newmann /
npub1tdz…f7wk
2024-08-15 13:24:31
in reply to nevent1q…ktks

Bashee Von Newmann on Nostr: The scheme relies on nip04 with an unpadded payload, meaning the encrypted length ...

The scheme relies on nip04 with an unpadded payload, meaning the encrypted length matches the plaintext. If a relay knows the Web Service API, it can potentially infer communication details. This risk is higher if using a relay without AUTH support—without it, anyone could analyze the traffic.

Replay attacks seem possible, allowing a relay to repeatedly trigger actions like "delete first item" until everything is gone.

Don't get me wrong—this is awesome technology, but it's not fully secure (yet?).
Author Public Key
npub1tdzespaljdwacturgpvzr08drj9qthlw0jqtqqxrx7axh59d0rksp0f7wk