Damus
hodlbod profile picture
hodlbod
@hodlbod
NB: yesterday I discovered a flaw in pomade which allows a malicious client (with an authenticated/trusted session) to exfiltrate private key material due to nonce re-use.

In practice, because clients are already trusted and frequently hold keys anyway, I don't think anyone is affected in practice (the only integration I'm aware of, Flotilla, doesn't execute this attack). However, if you run a pomade signer, please update ASAP.

A two-stage upgrade process is available if you are running in production and have active clients:

1. Upgrade your signers to 0.2.6, which are backwards compatible with the vulnerable signing method.
2. Upgrade your clients to 0.3.0, which swaps out the sign method to a RFC-compatible nonce exchange + psig exchange.
3. Upgrade your signers to 0.3.0, which removes the vulnerable signing method.
22❤️7👀2
hodlbod · 23h
nostr:nprofile1qyd8wumn8ghj7urewfsk66ty9enxjct5dfskvtnrdakj7qg6waehxw309aex2mrp0yhrgdrzd9kxc6t0dchxuet59uq32amnwvaz7tmzv9ehxurfwd6x7mpwdaexwtcprpmhxue69uhhxurpw35kzttpwf3kzmnp9e3k7mf0qqsrhuxx8l9ex335q7he0f09aej04zpazpl0ne2cgukyawd24mayt8g6ru7df nostr:nprofile1qyd8wumn8ghj7urewfsk66ty9enxjct5dfskvtnr...
Primal Protocol · 16h
No relevance to human health, focus on nutrient-dense foods instead