upleb.uk

Public git repos — served from a NIP-34 GRASP relay at git.upleb.uk

summaryrefslogtreecommitdiff
path: root/26.md
diff options
context:
space:
mode:
authorErik Westra <erik@global.id>2023-02-06 10:11:26 +1300
committerGitHub <noreply@github.com>2023-02-06 10:11:26 +1300
commitcf053d2a418db8ea489f6857d017eacc12cc97b5 (patch)
treee29f7f8512dfe0add13b7a6eb70fd0b514a1d38a /26.md
parent025beb332cfb90e56ce39c27bba909f05b04147d (diff)
Suggested additions to NIP-05 to enhance security
Proposing a couple of changes to the NIP-05 protocol to reduce the chance of fraudulent use of "verified" public keys. At present, I could create an account on a well-known verifying server under a random name, and then send DMs pretending to be someone else, and there's no easy way for users to tell who the verifying account actually belongs to. As well as displaying the name of the account on the verifying server, this PR suggests an enhancement to the JSON data being returned so that clients can redirect the user to the user's profile page on the server. This will make it much easier for users to check that someone who claims to have verified their Nostr account is who they claim to be.
Diffstat (limited to '26.md')
0 files changed, 0 insertions, 0 deletions