šŸ”‘ Boost your account security with NIP-9999! šŸŽ‰

This proposal brings subordinate keys (nsub) and revocable delegation proofs to Nostr, delivering enhanced security and scalability for key management. 🌐check out the article,written by nostr:npub1gkgyk28lurjuhyfjlxsga9mw6lc0c47c8pmcr65usre9d3qjcx6q9cyk5m nostr:naddr1qqnyuj2s95unjwfe94c8yefdv9k8q6rp94nx7u3dvejk2erzv93kkttgd3cnqef4qgsytyzt9rl7pewtjye0ngywjahd0u8u2lvrsaupa2wgpujkcsfvrdqrqsqqqa280j9mqg

Reply to this note

Please Login to reply.

Discussion

Not sure how to comment on the article itself so I’ll put my brief thoughts and suggestion (use case) here.

1. I love the idea and it would be very useful and valuable to Nostr.

2. Use case. Re: delegation (ie team members posting content)

It would be great if there is a way during the revocation process to identify which post of the delegatee should be kept vs removed.

Since I haven’t yet seen a delete or edit and rebroadcast function for Nostr, this may not be possible to delete malicious notes.

But I can imagine a scenario where a team member (nsub) has posted 1000 notes then They go rogue and start posting junk…I’d want to keep the 1000 proofs of work (notes) but revoke or delete the malicious and recent ones.

Similarly it might be nice to tag or otherwise appended/identify notes with a ā€œrevoked nsubā€ or some identification so that readers know the 1000 notes were posted by a team member that was removed,

Or, I think it was Facebook did this for biz profiles, the admins could see what post was actually posted by another admin or moderator…I don’t Recall, if everyone could see that, or if it was only Admins that could, but in this case for Noster, it would be nice that whenever an in sub posted, it was identifiable with a particular person, perhaps as a tag or something so that viewers know it is from a representative and a real human in the organization instead of just the brand at large.

you may just open the article and click on the comment icon it will pop up the comment section šŸ™

Ok I think I did that…

In the lower left corner of the app (on iOS) I pressed the comment button and added it there as well.

I see there are apparently 2 comments on the article now.

However in YakiHonne, when viewing the article, where / how should I see other comments? When I click the comment bubble it only slows me to write another comment

I’ll move this to a place that is better suited for discussion. Awaiting some advice as to where.

Long press the comments button, and you’ll see all the comments.

Thanks!

I must not be as smart as I thought LOL

These need cases match the existing intent of the NIP. But I was exploring the attack vectors, and there is too much vulnerability for this. Likely won’t work. And too much governance passed to the relay. I’m going to have to reapproach the solve, which is needed. But this may not be it and I’m stepping away from the NIP. I’m a noob on the protocol so sorry about my learning curve.

This sounds cool but I would prefer we have a way to secure our actual nsec address before doing this.

Right now deep storage of your nsec would be too inconvenient. With this NIP, it would become convenient as only delegate nsubs would be out in the world, treated as we treat nsecs now, and would be revocable.

I know there is an app to store it in, but that’s just trading one attack vector for another.

I wonder if there is a way to make your nsec only visible client side, so there is no way to extract it from the client itself.

Sort of how you can use a cloud storage app that has client side encryption so that the server maintainers don’t have access to your info.

Right now, my biggest worry, especially with most of the clients being open source, is that someone will figure out a way to gain access to a user’s nsec.

My vision on this, especially for high value brand accounts, would be a never-seen nsec on hardware, or a simple highly specialized and secure application, that's just used to sign nsub delegations and revocations.

Here’s the current draft of the idea in GitHub, where deeper discussion likely belongs… Needs both dev and UX feedback to clarify capability of protocol to handle the change, and the importance of the change for user security and adoption.

https://github.com/swbratcher/nips/blob/master/NSUB.md

Nice proposal. Keep up the good work

Game-changer for Nostr security! NIP-9999 redefines key management with innovation and scalability!