dtonon on Nostr: How can they tied someone else pubkey to their name? NIP-05 includes the pubkey, the ...
How can they tied someone else pubkey to their name?
NIP-05 includes the pubkey, the client verify that it matches with the pubkey of the (signed) kind:0 profile where the NIP-05 is saved, that's all.
Signing the NIP-05 doesn't improve this process.
Actually, signing NIP-05 could prevent someone, after hacking the server, from modifying NIP-05 itself. But it is a borderline case, adds a layer of complexity, and seems unnecessary for a simple identification tool.
Published at
2024-09-27 08:03:08Event JSON
{
"id": "00003f45c25d9ba28eec105a7113db4d694df09e42a77bf103eb46f3d517f82c",
"pubkey": "7bdef7be22dd8e59f4600e044aa53a1cf975a9dc7d27df5833bc77db784a5805",
"created_at": 1727424188,
"kind": 1,
"tags": [
[
"p",
"acf88a0308156dd1b3f9de7573f88dd03dea512afadfa37ac35bcf66906d5d4c"
],
[
"p",
"76c71aae3a491f1d9eec47cba17e229cda4113a0bbb6e6ae1776d7643e29cafa"
],
[
"e",
"f86e0c742c27ccef50cefba43d057957a64652ba9c92a6be9b87a9ba033503fa",
"wss://chorus.mikedilger.com:444/",
"root"
],
[
"e",
"0515a9346e743f6b2b26e756a003a6d2741c412b12fdcf43c2a819e5fef308c6",
"wss://nostr.fmt.wiz.biz/",
"reply"
],
[
"nonce",
"5534023222112876808",
"18"
]
],
"content": "How can they tied someone else pubkey to their name?\nNIP-05 includes the pubkey, the client verify that it matches with the pubkey of the (signed) kind:0 profile where the NIP-05 is saved, that's all.\nSigning the NIP-05 doesn't improve this process.\n\nActually, signing NIP-05 could prevent someone, after hacking the server, from modifying NIP-05 itself. But it is a borderline case, adds a layer of complexity, and seems unnecessary for a simple identification tool.",
"sig": "4b4ee9978a4f4cd702314f8f9951d9ac86f2ebb7db2ce1a79a79d8e54eb9a43eb5c2aebdf7fba6e3572d5355b72995ea0b12192b0493f85467491f0c41f97b2d"
}