Terrible idea Vitor.
If my Nostr private key is compromised, I would still want to send some message from my account to re-direct my subscribers.
In your scenario an account thief could nuke my account and prevent me from using it.
Terrible idea Vitor.
If my Nostr private key is compromised, I would still want to send some message from my account to re-direct my subscribers.
In your scenario an account thief could nuke my account and prevent me from using it.
What if the attacker does that first?
I can verify myself via other accounts or other social media. However, I would still want to post from my account if it was compromized.
But again, how do other people know it is you posting? The attacker can literally send your followers to anywhere the attacker want. There is no way to know which events are yours and which ones are the attackers.
Your post to lead your followers to a new key is extremely dangerous.
An attacker can send messages from my account before I even know that my key is compromised.
When my account is compromised, both the attacker and I can post from my account, as long as your idea isn't implemented.
In such a scenario I will post that my account is compromised and provide *evidence* via other social media accounts. The attacker can't do that.
I could also prepare in advance by setting up 1-2 backup nostr accounts that only I have access to, which are unlikely to be compromised at the same time.
Your idea would prevent me from posting from my account, and that is very dangerous.
Do you really think attackers don't already have this tooling? It's already coded. It's quite literally 20-30 lines of code to delete all your events from all relays.
Why would all relays support such a tool?
They already. Most of them.
My thinking is that ultimately it is more hazardous for an attacker to have your key and use it for bad actions that could seriously jeopardize you than it is for you to lose access to your account. Right?