so private-key is the main key here, i have backed it up safely, but I need to enter it again on any app whenever I need to sign-in. What if that app is compromised ?? Can they leak my private key ??

Already shared my private key with Alby, snort.social, iris etc.

Reply to this note

Please Login to reply.

Discussion

Yes, your private key is sensitive. So you want to enter it sparingly. On mobile stick with highly reputable and open source clients. On the computer load your private key in Alby then login using alby. Most web clients support this and your private key is never shared with the client.

thanks will take care of this EVERYTIME

The next step for you is to copy the Lightning address you created in Alby and add it into your profile in the field that says Lightning address or Lightning tips. Once you do that we will see it and can #zap you. And Alby also lets you send zaps as well.

It’s called a custodial wallet because it’s managed by a third party. After you have had some time to explore how it works, you should look into using non-custodial wallets as well. Again, feel free to #AskNostr if you get stuck on anything!

Thanks, I did that. Understanding bit at a time. Thanks a lot nostr:npub1aeh2zw4elewy5682lxc6xnlqzjnxksq303gwu2npfaxd49vmde6qcq4nwx

Right. You’re correct that your private key should always be protected. By entering it directly into a client you’re not actually sending it to or sharing it with them, your browser is using it to sign events for you. It’s much safer to sign out of those clients and only use the Alby extension to access them in the future. This way you aren’t taking the risk of having it copied into your clipboard where you can accidentally paste it publicly.

yes, set up Alby extension, exploring some settings there.