Join Nostr
2026-01-26 20:10:14 UTC
in reply to

Lez on Nostr: Can you elaborate on the replay attack vector you mention in the README which affects ...

Can you elaborate on the replay attack vector you mention in the README which affects the BUD-01 auth spec? What's the risk / scope of the attack? Can you provide an example?

Since `created_at` is part of the auth event, in my opinion it's easy to limit its scope on the server side to almost irrelevant by checking if the event is in the near past. Or would it break the functionality somehow?