I am currently looking for security-oriented reviews, so if you're interested in using this project for your client, please take a look at PROTOCOL.md and tell me if you see any major attack vectors! Of course, an email-based recovery protocol can only be so secure (email providers, senders, clients, and signers are all assumed to be somewhat trustworthy). If you really want to go deep, a review of the signer code would also be helpful.
Finally, if you'd like to run a signer please let me know and I'll add your signer to my master list of recommended signers.
{
"id":"b6630963b2cb86666e6465e8fdd63e455732c596d714666c568cdb2eb5364d3e",
"pubkey":"97c70a44366a6535c145b333f973ea86dfdc2d7a99da618c40c64705ad98e322",
"created_at":1768245208,
"kind":1,
"tags": [],
"content":"Pomade is getting closer — take a look below for a demo video, or try it out yourself at https://pomade.onrender.com.\n\nhttps://coracle-media.us-southeast-1.linodeobjects.com/pomade_demo_3.mov\n\nFor more details, take a look at the repository at https://github.com/coracle-social/pomade.\n\nI am currently looking for security-oriented reviews, so if you're interested in using this project for your client, please take a look at PROTOCOL.md and tell me if you see any major attack vectors! Of course, an email-based recovery protocol can only be so secure (email providers, senders, clients, and signers are all assumed to be somewhat trustworthy). If you really want to go deep, a review of the signer code would also be helpful.\n\nFinally, if you'd like to run a signer please let me know and I'll add your signer to my master list of recommended signers.",
"sig":"99d48dc20df924d854675489227cfb9d69ef69853ca404ac0495955bd8187fcad2baa7978614120b231c4715bf1292978063b9afef3efb05e9633c585d8e37fc"
}