That's assuming that there is no bad actors or that there wont be malicious actors when nostr catches on. We shouldn't normalise pasting any kind of private keys into any kind of app, website or browser. That's why we have signing devices.

Reply to this note

Please Login to reply.

Discussion

Let's give more valid options:

1. Open source software with auto updates turned off (eg. Browser extensions like Alby)

2. Open source with updates off like apps from fdroid.

3. Hardware signing devices like Ben arcs esp32 device.

4. Nostr nsecbunker on a 247 server.

1 and 2 are objectively riskier than 3 and 4 because 3 and 4 are more likely to have your nsec stored on a device with less consumer grade software and less casual and social activities performed on them making them less likely to receive malware and viruses.

You can switch of updates for browser extensions by going to the extension details page and toggle the switch next to "Allow automatic updating".

How do I then update Alby extension?

So you mean extensions like Alby as Signing Devices or some hardware devices?

Extensions, a local wallet or a hardware device. Anything device that signs your request local before broadcasting them to the network. Just like we know it from Bitcoin. So yeah Alby, Electrum, anything is better than copying a private key into a website or app.