SHA256 length extension attack: https://www.youtube.com/watch?v=gOIBUe1fjX0
Just for entertainment and education. This isn't a problem in nostr because we use a signature, not a MAC (and nostr messages can't be extended beyond the closing brace).
Login to reply
Replies (1)
Also, the double sha256 fixes this (just hash it twice)