Nostr login was and is a horrible idea.

Reply to this note

Please Login to reply.

Discussion

I’ll never know what this means

👀 well yeah?

When key management? It’s sad that the biggest security issue on this platform continues to be ignored. Odds are many accounts are already compromised, and users just don’t know it yet. The longer developers dismiss this, the more damage it will cause and eventually, it’s going to drive people away. Tick tock 🍿

Frostr is being worked on and AFAIK can be used today, they're just working on the ux

Noobs won’t touch it.

Key management is already hard, throwing FROST into the mix without clean abstraction is UX suicide.

Thresholds? Coordination? Lost shares?

Without solid recovery, you’re one mistake away from a brick 🚩

Okay, I was wrong!

Never used it. Just a lightning login user

I like Lightning login as well

I mean, they way CoinOS implemented it. Id imagine that the server just presenting a challenge that youd need your private key (or a signing app) to prove would be reasonably secure

But storing everybodys private keys on a server, even if salted or whatever they were doing, is just retarded

Through pasting your private key or via an extension? Or generally?

😳😳

Maybe if disposable keypairs were used this would be more viable.

Sharing your "main" identity with a service provider is dumb.

nostr:nevent1qqsq7qcgaafkr7g4ry5z5jj3wu4xewdntdunzmn9s6lkrfvyy0tat7sprpmhxue69uhhyetvv9ujuumwdae8gtnnda3kjctvvqzeh9

Any kind of login is a horrible idea. All you should be is present and active.