<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-06-05T14:14:21&#43;02:00</updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by dzlandis</title>
  <author>
    <name>dzlandis</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub18zs9fsm4zkacu0k4dumnnpnxq62kjcfva8aekft0m0jynmfrvs4qafffdd.rss" />
  <link href="https://nostr.ae/npub18zs9fsm4zkacu0k4dumnnpnxq62kjcfva8aekft0m0jynmfrvs4qafffdd" />
  <id>https://nostr.ae/npub18zs9fsm4zkacu0k4dumnnpnxq62kjcfva8aekft0m0jynmfrvs4qafffdd</id>
  <icon>https://cdn.nostr.build/i/1c0c827579f7c27991b90412c26c8331bda44193f8c413e9069209e15b1fc255.png</icon>
  <logo>https://cdn.nostr.build/i/1c0c827579f7c27991b90412c26c8331bda44193f8c413e9069209e15b1fc255.png</logo>




  <entry>
    <id>https://nostr.ae/nevent1qqsdut2us5k9hf4eg8pu5c4e3vl4kfl6ec4jjegjqwdwlwareg2f34czyqu2q4xrw52mhr3764hnwwvxvcrf26tp9n5lhxe9dld7gj0dydjz5k3ysdu</id>
    
      <title type="html">Your Nostr private nsec key could have been exposed simply by ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdut2us5k9hf4eg8pu5c4e3vl4kfl6ec4jjegjqwdwlwareg2f34czyqu2q4xrw52mhr3764hnwwvxvcrf26tp9n5lhxe9dld7gj0dydjz5k3ysdu" />
    <content type="html">
      Your Nostr private nsec key could have been exposed simply by visiting a website. 😱 &lt;br/&gt;&lt;br/&gt;I recently found and privately disclosed a high-impact vulnerability in Flamingo, a Nostr browser extension similar to nos2x and Alby that lets websites request your public key and ask you to sign Nostr events without handing every site your private key.&lt;br/&gt;&lt;br/&gt;While reviewing the code, I noticed that Flamingo’s webpage-to-extension message bridge was too permissive. A normal webpage could reach an internal extension method that should only have been available to Flamingo itself, allowing the page to export the stored nsec.&lt;br/&gt;&lt;br/&gt;The maintainer responded quickly and shipped a fix in v0.1.1. Page-originated calls are now restricted to the intended public NIP-07 methods, while sensitive extension-only methods are blocked from websites.&lt;br/&gt;&lt;br/&gt;If you use Flamingo, make sure you are updated to v0.1.1.&lt;br/&gt;&lt;br/&gt;Proud to have helped catch this before it could do real damage, and shoutout to the maintainer for handling the report quickly and cleanly.&lt;br/&gt;&lt;br/&gt;&lt;video controls width=&#34;100%&#34; class=&#34;max-h-[90vh] bg-neutral-300 dark:bg-zinc-700&#34;&gt;&lt;source src=&#34;https://blossom.primal.net/ef8b7df82b79fa4fbc742441fd678ae67e50f37d2041f3fc2dc2a5a62b7a3f03.mp4&#34;&gt;&lt;/video&gt; 
    </content>
    <updated>2026-06-11T13:14:38&#43;02:00</updated>
  </entry>

</feed>