Content pfp
Content
@
0 reply
0 recast
0 reaction

Daniel Fernandes pfp
Daniel Fernandes
@dfern.eth
Cool that Nostr chats are getting a security audit from @paulm of noble-cyphers fame. Wondering what kind of security guarantees Nostr DMs provide and how Farcaster, Status, and/or XMTP compare https://x.com/paulmillr/status/1803970529629487114
3 replies
0 recast
19 reactions

Paul Miller pfp
Paul Miller
@paulm
.@cassie made fc dms which are superior in security (signal ratchet), but it seemed quite complex. It’s unclear if the ratchet is still being used. Nip44 is very simple and doesn’t guarantee much. In fact you can check this in its disclaimers section. It’s just a good start. No one uses status. Smtp leaks metadata everywhere and is not e2ee.
1 reply
0 recast
1 reaction

Cassie Heart pfp
Cassie Heart
@cassie
DCs on Warpcast lost E2EE a while ago so we could support web DCs, but we'd like to revisit this some point soon now that PRF is on the menu
1 reply
0 recast
0 reaction

Paul Miller pfp
Paul Miller
@paulm
What’s PRF?
1 reply
0 recast
1 reaction

Cassie Heart pfp
Cassie Heart
@cassie
webauthn's PRF feature — can provide a way we can restore E2EE for DCs on web by "unlocking" access via passkeys, but of course with the caveat that web browsers still have a much bigger blast radius for attack compared to an app
0 reply
0 recast
2 reactions