Replying to Avatar hodlbod

**Security Update**

I've got some bad news for you guys. This morning, as I was adding error handling to flotilla, I discovered that Coracle has been sending user session objects to bugsnag when reporting errors.

Who is affected: Users who triggered an error in Coracle while signed in with their private key, since December 5th 2023.

What I've done:

- I immediately released a new version of Coracle, both to web and to zap.store

- I have deleted the affected apks from my releases

- I have deleted all my error data from bugsnag

- I have deleted my bugsnag project and rotated my api key, so lingering error reports will be dropped

- I have audited my code for use of the session object to ensure nothing else like this is happening

What you should do:

- If you're logged in with your private key, log out

- Hard refresh the page to ensure you have the latest version of Coracle

The bottom line is that if you signed in to Coracle with your private key, it has been shared with me and with bugsnag. In practical terms, your keys should still be secure, since they were sent over TLS, and have been deleted. But there is no guarantee I can offer that they are in fact gone.

I take my users' privacy seriously. My error reporting implementation doesn't record user IPs, it redacts identifying data, and it allows users to opt-out. I also warn the user when they attempt to enter an nsec into a text field. In this case, I simply screwed up, and I sincerely apologize. Reply to this note if you have any questions.

Some fuck up was bound to happen with using nsecs to login

nostr:nevent1qqsrz6g5ds3dfht4a6zgdt7k593ujhnrz4njn6mke2fmpwxjc3sgafcpzemhxue69uhhyetvv9ujucm0d9hx7uewd9hj7q3qjlrs53pkdfjnts29kveljul2sm0actt6n8dxrrzqcersttvcuv3qxpqqqqqqz3l4dcc

Reply to this note

Please Login to reply.

Discussion

I'm one of those normies that's still using Amethyst and doesn't know what NSec is.

Is it specific to webapps, a specific platform, or some type of password manager thing?

it's your nostr secret key, nsec

if you are using amethyst either you put it into amethyst or you put it into amber

if you don't have amber, get amber

i kinda had problems with amber though, and amethyst, with it popping up all the time and i couldn't figure out how to fix it

so, yeah, my guess is you have an nsec in amethyst and never put it anywhere else, but it is at risk of being lost if you don't put it somewhere else...

I just saved my nsec and npub in my password manager as a note

nsec is your secret key. You must have input it to login to Amethyst

It's not specific to webapps or any platform. You can use it to login to any Nostr app

Best to avoid using your nsec anywhere and use keystore apps like nsec.app or Amber