I think it's worth knowing that the cryptography in Nostr appears to be a wreck. Here's a paper from EuroS&P this year, also presented at Black Hat on the crypto track: https://eprint.iacr.org/2025/1459.pdf The vulnerabilities here are pretty :yikes: * The event protocol that drives the system doesn't authenticate public keys, so asymmetric signatures are performative: attackers that can intercept messages (Nostr ser…
> The event protocol that drives the system doesn't authenticate public keys, so asymmetric signatures are performative: attackers that can intercept messages (Nostr servers, the presumed adversary of an E2EE messaging system) can just swap out keys and re-sign. This is completely nonsense, most clients do in fact check signatures. All relays do as well. > Two major clients, the mobile phone Damus app and the web Iri…
Nostr
241–250 of 347 posts
Re: Nostr
#242I think it's worth knowing that the cryptography in Nostr appears to be a wreck. Here's a paper from EuroS&P this year, also presented at Black Hat on the crypto track: https://eprint.iacr.org/2025/1459.pdf The vulnerabilities here are pretty :yikes: * The event protocol that drives the system doesn't authenticate public keys, so asymmetric signatures are performative: attackers that can intercept messages (Nostr ser…
Unfortunately this paper doesn't live up to its goal of being a cheap attack on Nostr. The fact is that clients do verify signatures from events received from servers, that is in the protocol specification and should be obvious to anyone mildly honest. The entire assumption of the paper is that clients don't do that and it is void. Yes, they did find a couple of clients 2 years ago that didn't verify signatures -- so…
Re: Nostr
#243I think it's worth knowing that the cryptography in Nostr appears to be a wreck. Here's a paper from EuroS&P this year, also presented at Black Hat on the crypto track: https://eprint.iacr.org/2025/1459.pdf The vulnerabilities here are pretty :yikes: * The event protocol that drives the system doesn't authenticate public keys, so asymmetric signatures are performative: attackers that can intercept messages (Nostr ser…
So, I was part of the Nostr community for quite a while and was the author of a popular Nostr extension for Safari, before eventually giving up on Nostr for various reasons. I haven't read that entire paper. Mainly, I skipped to the section you mention here: > The event protocol that drives the system doesn't authenticate public keys, so asymmetric signatures are performative: attackers that can intercept messages (N…
Re: Nostr
#244Earlier quoted context omitted.
> The event protocol that drives the system doesn't authenticate public keys, so asymmetric signatures are performative: attackers that can intercept messages (Nostr servers, the presumed adversary of an E2EE messaging system) can just swap out keys and re-sign. This is completely nonsense, most clients do in fact check signatures. All relays do as well. > Two major clients, the mobile phone Damus app and the web Iri…
I don't think you can say "this is complete nonsense" and "this has since been fixed" in the same comment. Also: don't use ECC signatures as MACs. Signatures are not MACs.
Re: Nostr
#245I think it's worth knowing that the cryptography in Nostr appears to be a wreck. Here's a paper from EuroS&P this year, also presented at Black Hat on the crypto track: https://eprint.iacr.org/2025/1459.pdf The vulnerabilities here are pretty :yikes: * The event protocol that drives the system doesn't authenticate public keys, so asymmetric signatures are performative: attackers that can intercept messages (Nostr ser…
why is this the first time that I came across these issues. Someone should talk about these issues asap. What federated platform might be the more secure tho protocol wise, bluesky (at protocol) or fediverse
Re: Nostr
#246I've revisited this idea/protocol a few times and still have my doubts: * is there even a need for it? I would say that most people are quite happy with centralized platforms; I don't see it changing anytime soon (why?) * wouldn't we end up in the centralized world anyways? Even though there could be multiple NOSTR clients and relays, we all know how network effect works - people will flock to a single or a few best…
Re: Nostr
#247Earlier quoted context omitted.
It's quite common for people with rather controversial topics to have backup accounts listed in their bio because centralized platforms are so prone to deplatforming people. If that's acceptable to you, then nostr probably isn't for you. I prefer not to beg anyone for permission to publish my opinions on the internet.
Why not to have a website then? That's the only thing that where the content is truly Yours. In NOSTR, even though yes there is more than one relay, but you still need their permission to publish; and yes, you can run your own relay - but you might host your own website too - no need for new apps and protocols to do this
In your example you can think about nostr as a protocol on top of "your own websites" that allows all people with "your own website" to effectively communicate and live interact with each other. And creating "your own website" is just a matter of clicking a button in any nostr app that generates private key and public key pair.
Re: Nostr
#248Earlier quoted context omitted.
>Software is inherently apolitical. Claiming otherwise would be like saying that a hammer or drill are political, which is absurd. No one sells "apolitical hammers" or "apolitical drills." If one has to specify that software is apolitical, it isn't. No software exists in a vacuum, even the license terms are a political statement. Certainly nostr was created as an expression of fiatjaf's specific political ideals, and…
> If one has to specify that software is apolitical, it isn't. That conclusion doesn't track. In a time when a lot of software has become politically charged, it's perfectly reasonable to specify when that isn't the case. > No software exists in a vacuum, even the license terms are a political statement. Software doesn't exist in a vacuum, but not all licenses are the same. There are many licenses that don't place an…
Or they find that this is the only place their politics are accepted. A nazi bar is not better than any other bar.
Re: Nostr
#249I think it's worth knowing that the cryptography in Nostr appears to be a wreck. Here's a paper from EuroS&P this year, also presented at Black Hat on the crypto track: https://eprint.iacr.org/2025/1459.pdf The vulnerabilities here are pretty :yikes: * The event protocol that drives the system doesn't authenticate public keys, so asymmetric signatures are performative: attackers that can intercept messages (Nostr ser…
> The event protocol that drives the system doesn't authenticate public keys, so asymmetric signatures are performative: attackers that can intercept messages (Nostr servers, the presumed adversary of an E2EE messaging system) can just swap out keys and re-sign. This is completely nonsense, most clients do in fact check signatures. All relays do as well. > Two major clients, the mobile phone Damus app and the web Iri…
Re: Nostr
#250Earlier quoted context omitted.
It's still pretty affordable and not-hard to run your own Lightning node; The pseudo-bank hosted wallets people use (e.g Wallet of Satoshi) is purely out of convenience. The real lesson is that most people don't care enough about the underlying risks - they care about convenience.
How much BTC do you need to run a node? And what are the failure modes if the node goes down or becomes network unreachable or something? I'm not trying to be critical, just curious myself what happens if I run a node. Would be happy for any resources you have on hand if that's too much for an HN comment.
Hopefully future versions of Start9 or Umbrell make it easier. Or some hybrid solutions like Greenlight/Breez or Spark.