Yes, but an attacker will also be able to decrypt messages encrypted to the old key. Also, the old 10044 is validly signed forever, so an attacker can actively seed these announcements in any place that hasn't received the update. Inkan fixes that as a by-product of its key rotation system, which records revocations on-chain. I may try to add DMs, right now I'm exploring if a double ratchet is feasible.
Login to reply
Replies (1)
I’m not sure what an attacker gains by spreading an old 10044 event elsewhere. Clients should be fetching 10044 events from the user’s write relays / DM relays anyway.
I don’t think putting it on-chain fundamentally solves the issue of senders not getting the latest update in time. It feels more like a different source of truth, querying relays versus querying the chain.