Damus
Caek Islove ๐Ÿฐ ๐Ÿ’– · 2w
Please excuse the slop, but have you considered potential mitigations for this issue? I thought maybe adding an additional trust layer for "really trusted node", but I suspect that would lead to the s...
Caleb James DeLisle profile picture
If you scroll to "Security Analysis" a fair bit of ink is spilled on this issue. It's THE obvious one...

Now there are two mitigations that can help here:
1. Don't trust a record until you've seen it from multiple nodes, and you can setup whatever rules you want here
2. Make nodes sign messages so that if they ever emit a fictitious record, they have no deniability

That said, the slop machine is a little bit autistic here because the situation with certificate authorities is the same if not worse - there's so many of then any everybody trusts all of them for all domains...
2
Caek Islove ๐Ÿฐ ๐Ÿ’– · 2w
#1 actually sounds like it would be pretty solid. Thanks for your thoughts!
jaff (employed) · 2w
nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqmh5a6mhm4u78glqxhltq7uexv6kddphycthlguvn0ux8ch72tc8qsf8cpz nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqj4cpas2gpjsm7e302nmy653gw8ckmpt0chysvz3ep46ephq6sg7qh0cvrl nostr:nprofile1qy2hwumn8ghj7un9d3shjtnyd968gmewwp6kyqpqprdy6x4ccuupdaepf...