Replying to Avatar Nusa

We could make it curve-agnostic, using something like PKCP as a bridge.

https://github.com/pubkeychain/pkc-protocol

If you have an identity chain with pubky and nostr keys in PKCP you get a two-for-one deal, linking of id across protocols and nostr key rotation.

There's still the question of what the keys would even be signing. I don't see much point in signing individual events in the Pubky world. Of course you could do that, but it'd be like wearing a rain coat under an umbrella. If the umbrella is big enough then the rain coat is just extra weight and stuffiness.

I guess there might be some niche ultra-high-assurance use cases but I can't think of one.

Reply to this note

Please Login to reply.

Discussion

Depending on the client and the use case, you could be leaning into one or the other. One might want individualy signed notes in the social network context and boards in the project management context.

Not saying I have all the answers. It’s just possible to have them coexist.

I just mean if it's on your board then we can consider it to be yours. Works for social use cases and most other use cases.

So a Twitter clone, as long as it's pulling from each person's board then I'm not sure why bother signing the individual notes? If someone is saying "yo guys that note is injected, don't believe it" then it'd be pretty easy to diagnose, because it wouldn't exist on that person's board when you went to cross-check.

Maybe in some situation where there's a high injection risk and the impact of being misled by an injected note is quite high then sure, sign all the notes. Hard to think of such a case though.

I’m thinking more along the lines that we have a lot of very opinionated software and a lot of users who just don’t want to deal with the details. This makes protocol hopping possible so users can choose the best software for a given use by some other metric.

Ah okay see where you're coming from