Global Feed Post Login
Replying to Avatar Vitor Pamplona

What if DMs were device-based?

We could use a secret from the device to create a new private key to use exclusively DMs. Since the new DM key can stay in the device's secure element, there is no way for any other device to access your DMs, even if you keys leak (they will inevitably do).

Pros:

- avoids leaking DMs when the nostr key leaks.

- DMs that expire when the phone expires

Cons:

- users cannot migrate the DM history to a new phone/client

With private group DMs, we could add all device keys in a single DM message so that current devices of a user can read the DM history.

75
756240d3... 2y ago

Keys on proprietary hardware are not secure. A better solution would be an open source security token as described here for email:

https://www.kuketz-blog.de/gnupg-e-mail-verschluesselung-unter-android-nitrokey-teil4/

Even more secure would be an open source hardware wallet with display and seed backup on steel with nostr and openpgp feature. nostr:npub1tg779rlap8t4qm8lpgn89k7mr7pkxpaulupp0nq5faywr8h28llsj3cxmt

Reply to this note

Please Login to reply.

Discussion

No replies yet.