Why Nostr? What is Njump?
2023-06-17 21:17:17
in reply to

fishcake on Nostr: I think the main problem lies (and I am speculating here since I just woke up and ...

I think the main problem lies (and I am speculating here since I just woke up and didn’t check the nips yet) in how the event is signed and verified. I think it allowed attacker (somewhat good one in this case) to manipulate the type of the event and potentially some tags. This means that they could have taken any events that are stored on relay and change what they could without breaking signature. Then, any thing like spam reports, emotions, ets, could be converted into DM, or normal note. It’s possible some other method was used but that’s the best I could imagine in my sleep without checking how actuality is. 🐶🐾🫡
Author Public Key
npub137c5pd8gmhhe0njtsgwjgunc5xjr2vmzvglkgqs5sjeh972gqqxqjak37w