NIP-04 by itself is not vulnerable and is secure against these “attacks” as signatures exist
Login to reply
Replies (1)
AES-CBC (the core of nip04) has been removed from many crypto suites, including TLS 1.3, due the many security issues in poor implementations, mostly related to oracle padding attacks, which are also possible in nip04.