pull down to refresh

Well, I don't audit Alby Hub so I can't tell you for sure, but in general, if you have lnaddr / lnurlp exposed, even through tor, then you're potentially still exposed? If you only have NWC and no listeners whatsoever, then maybe you're good.

But don't take my word for it please, because I haven't checked.

149 sats \ 1 reply \ @bumi 10 Sep

NWC is providing a limited communication protocol between apps and a wallet through relays. This the wallet itself does not need (and should not be) publicly accessible for it to be used by any apps and doing things like lnaddr/lnurlp.
A LNURL just needs a NWC permission to create an invoice.
it's another layer.

reply

Thanks for coming over!

So if someone has a 3rd party distribution like Umbrel or Start9, and it takes a while for them to get an update, the thing to make sure is that:

  1. public access to the management interface is disabled (how?)
  2. in general port 8080 (or whatever is configured as the hub listening port) is firewalled

correct?

reply