Damus
Ostrich McAwesome profile picture
Ostrich McAwesome
@Ostrich McAwesome
I took notice of this account today, and want to first clarify that I am not affiliated with it. Looks to be someone's old account with a leaked nsec being puppeteered by a handful of trolls. Someone decided to take credit for the drama of the day it seems...

But there are some recent threats of exploiting #Mostr that I found quite fascinating. Not really the kind of exploit I'm interested in, but it sounds quite eggregious. It looks quite trivial to turn Mostr into a problem, attacking from either the Nostr or ActivityPub side, since it seems to blindly relay everything. You could just flood it with spam and it would do all the work of delivering it.

Someone should consider testing that. It sounds like a weakness to me.

2🫂1
Ostrich McAwesome · 108w
On that note, time for another lesson. You can't trust relays. That's not how I leaked people's IPs, but they are absolutely a vector for that. And if you post with more than one account without changing your IP first, anyone with access to the relay logs can connect your accounts to each other. ...
Alex Gleason · 108w
It does (mostly) blindly relay everything. But this is considered okay because of anti-spam mechanisms on clients, relays, and on ActivityPub servers themselves. That one annoying user was using a single pubkey and not actually doing anything new or interesting, except that he got an nsec that alre...