Global Feed Post Login
Replying to Avatar jb55

after working on Damoose (safari extension), it seems nostore is pretty insecure because it exposes your private key to the javascript environment.

Since we store your key in the iOS keystore, we can just access this from the plugin background process instead of the browser's javascript runtime environment.

We can sandbox the plugin process to disable outgoing networking connection, so it can only send messages to and from the browser, so it should be way more secure than what nostore was doing.

Avatar
Nice and Kind Vic 1y ago

wow. good to know.

nostr:nevent1qqs96t58lszflzkevzswdwyz2ts8s8x5ymgz8l3w3y6wv8pyqdgdxzcpz9mhxue69uhkummnw3ezuamfdejj7q3qxtscya34g58tk0z605fvr788k263gsu6cy9x0mhnm87echrgufzsxpqqqqqqzkpfk6h

Reply to this note

Please Login to reply.

Discussion

Avatar
kidwarp 1y ago

Yeah you can actually give Nostore permission to you credit card info and shit if your not careful…

Thread collapsed