Global Feed Post Login
Replying to Avatar Big Barry Bitcoin

Technically you never "log in", if you're on a website, you typically identify yourself with your npub (if you gave your nsec, the browser keeps that locally and works out the npub and gives that to the website). Then when you use the site, your browser signs all your posts on your behalf.

No one but you and your computer sees the private key. Malware may figure out how to steal your key from your computer but they don't pinky promise nothing.

If you use an app, hopefully you've chosen an open source and well trusted app. If you have, then you already know that the nsec is kept on your mobile phone and not given to the app developers. If you did not, let's say yes, they pinky promise. But you shouldn't trust a pinky promise.

Avatar
Medici 2y ago

Can a browser sign anything with only an npub? Spell check got me.

Reply to this note

Please Login to reply.

Discussion

Avatar
Big Barry Bitcoin 2y ago

No. A browser cannot sign anything with an npub, they can only use it to find things related to you that has already been signed and published (read only)

Thread collapsed