Content pfp
Content
@
0 reply
0 recast
0 reaction

Brian Li πŸŠπŸ‘Ύ pfp
Brian Li πŸŠπŸ‘Ύ
@bli
Got a question about signatures. If you’re looking to connect a wallet to an account with a signature, what would you use to prevent replay attacks? Farcaster uses the blockHash. OpenSea uses a random cryptographic nonce. Transactions use the nonce of the address. Which is right for linking accounts?
1 reply
0 recast
2 reactions

Greg pfp
Greg
@greg
For anything more than a weekend project I’d probs use the SIWE standard https://login.xyz/ It uses a nonce with an optional expiration timestamp There should be many open source examples of it
1 reply
0 recast
5 reactions

Brian Li πŸŠπŸ‘Ύ pfp
Brian Li πŸŠπŸ‘Ύ
@bli
Ty! What about if you have a mobile app and a website and you might have a changing domain/bundle identifier that is hard to verify?
2 replies
0 recast
0 reaction

Greg pfp
Greg
@greg
Hmmm I’m not sure. I feel like @horsefacts.eth might know the best approach
0 reply
0 recast
2 reactions

scottrepreneur pfp
scottrepreneur
@scottrepreneur
You can skip the domain check it your implementation. SIWE can help you validate the signed message contents and you can check those contents further.
0 reply
0 recast
0 reaction