Nostr'a Katılın
2026-07-23 21:15:13 UTC
in reply to

Caleb James DeLisle on Nostr: If you scroll to "Security Analysis" a fair bit of ink is spilled on this issue. It's ...

If you scroll to "Security Analysis" a fair bit of ink is spilled on this issue. It's THE obvious one...

Now there are two mitigations that can help here:
1. Don't trust a record until you've seen it from multiple nodes, and you can setup whatever rules you want here
2. Make nodes sign messages so that if they ever emit a fictitious record, they have no deniability

That said, the slop machine is a little bit autistic here because the situation with certificate authorities is the same if not worse - there's so many of then any everybody trusts all of them for all domains...