arthurfranca on Nostr: Did u read this issue? Tl;dr is that nostr security model when using nip07(or 46) is ...
Did u read this issue?
https://github.com/nostr-protocol/nips/issues/1439Tl;dr is that nostr security model when using nip07(or 46) is broken cause the nip07 extension grants full decryption rights to an app. We needed aead to include event kind info so to grant rights scoped to specific kinds.
If you r able to create a NIP that enhances nip04 with padding and aead (to include event kind as AD) or come up with another scheme to replace nip04|44 I'm sure people would be interested.
Published at
2024-10-25 15:07:51Event JSON
{
"id": "41723d3d31589afe9300bf1c99a183ef94fe3b0eb33f13b123938f7ffcd12289",
"pubkey": "fc7085c383ba71745704bdc1c6efcf7fab0197501de598c5e6c537ac0b32a4cb",
"created_at": 1729868871,
"kind": 1,
"tags": [
[
"e",
"5531cb3c595e3d085dd453282e80bd0822307b2a350fe58d582e97e17a12850b",
"",
"root"
],
[
"e",
"841c6ce0d43b18dfc4f93de514fac87943930bfbf5aa836696e46d54881e9aad"
],
[
"e",
"e32603ac42ad08663ee3bf4d9622d0db04f44e5a097b8eb242fccfdd9bddc5c6",
"",
"reply"
],
[
"p",
"4c800257a588a82849d049817c2bdaad984b25a45ad9f6dad66e47d3b47e3b2f"
],
[
"r",
"https://github.com/nostr-protocol/nips/issues/1439"
]
],
"content": "Did u read this issue? https://github.com/nostr-protocol/nips/issues/1439\n\nTl;dr is that nostr security model when using nip07(or 46) is broken cause the nip07 extension grants full decryption rights to an app. We needed aead to include event kind info so to grant rights scoped to specific kinds.\n\nIf you r able to create a NIP that enhances nip04 with padding and aead (to include event kind as AD) or come up with another scheme to replace nip04|44 I'm sure people would be interested.",
"sig": "8e9db3ea0112ad2f32d33f37b57003680eedd1f3a282f7e6e42cc9cc386df4710d6a827ec647ef3d5e9e75a05cba8bf7636a70729a319409435fb2c026cb1219"
}