pull down to refresh
0 sats \ 14 replies \ @ek 17 Dec 2023 freebie \ parent \ on: How private are the messages in a LN transaction? bitcoin_beginners
The funny thing is:
This is (one of) the first real vuln we have and it was disclosed publicly.
There were some people who thought they found something serious and did a responsible disclosure.
But all of them didn't do enough DD and just assumed it's a vuln and immediately contacted us, probably feeling FOMO because they might receive a huge bounty if they are the first to report, lol
Most funny was the guy who leaked his own IP address and then started to think he is now able to find out the IP address of everyone on SN with the same method, lol
Most funny was the guy who leaked his own IP address and then started to think he is now able to find out the IP address of everyone on SN with the same method, lol
I guess I might know what you are talking about? and about IP address, I tried different ways to test it. If someone keeps using the same IP, yes, it can be "dangerous", but then, even in this case, all you can know is where this user located, what did this person read and how long, what's his interests.
Maybe one account to read, one to post is the way š§
reply
yes it can be "dangerous", but then even in this case, all you can know is where this user located, what did this person read and how long, what's his interests.
You're onto something there :)
IP addresses are actually quite often not that useful but for some people, their IP address seems to be holy to them even though their ISP provider keeps changing it all the time and their ISP provider is basically already "mixing them" with other users (CGNAT) since we've run out of IPv4 addresses a long time ago.
reply
even though their ISP provider keeps changing it all the time and their ISP provider is basically already "mixing them" with other users (CGNAT) since we've run out of IPv4 addresses a long time ago.
oh I didn't know this š also something interesting I've learnt from a privacy geek friend - creating false trace is often better than trying to hide everything.
reply
false trace is often better than trying to hide everything.
Yes, hiding in the masses is better than to tell everyone that you have something to hide :)
reply
oh I didn't know this
so many ideas for blog posts, so little time, lol :)
edit: but somehow, there is always time to reply to people on SN, lol :)
deleted by author
reply