I really don't know what to do here about my profile being updated without me updating it. I assume my key is burnt somehow? Or is it some client that did something?

My private key was generated and used on astral.ninja for a day, entered into and used on damus.io/web for less than 10 minutes, entered into Amethyst and Daisy. Everything else has been via the nos2x extension.

I know this most likely doesn't mean anything, but the very first day that my LN address was updated was the same day that I tried Amethyst for the very first time, downloading the APK from Vitor's GitHub. I used a burner account at first then switched to my main account after a while.

Looking at the original relays that were seeing updates to my profile metadata, they weren't relays that I used. This leads me to believe the key is burnt?

I have over 3K followers and have worked really hard at that. I would have to have to start over. I really don't want to do that. It would essentially erase the last 6 weeks of doing nothing but living, breathing, and sleeping my desktop and phone.

Feeling lots of emotions right now.

Reply to this note

Please Login to reply.

Discussion

I've been hesitant to try out any mobile apps because I don't have a good way yet to manage the key outside of that app. I think NIP26 should solve that issue, but I need to understand it a bit better and a client to allow it to be used on.

That is worrying.

What change was made to your profile?

Amethyst displayed my LN Address field as blank, even though I'd set it previously in Damus. But it wasn't replaced with anything fishy. I set it again in Amethyst. Presumably it's good now. Snort is showing it as expected.

Mine was changed a dozen times over the course of 9 days.

Back and forth between your legit LN addr and a hacker's or changed to diff ones sequentially?

e.g.

yours, hacker's, yours, hacker's, etc.

or

yours, X, Y, Z

Publish your new pub. Folks who matter will follow back. Over a long time horizon those numbers mean nothing IMO. Having fun does! 😅

Have you checked if the wrong lightning address was used by another account?

It could be that your metadata were mixed up with some random account due to a bug in a client.

Similar thing happened to me. Started out using astral.ninja with alby extension.  I tried the snort.social client and used my alby extension to log in.

When I went back to astral I had to refollow everybody. I`m no techie at all,  just my observation. But I was only dealing with small numbers so it was not a big issue. But thousands would be a pain in the nether regions.

This about the LUD06 entry? you know it's pointing to your wallet right? So it's probably some client is expanding your LN address into the LUD06 field

It's absolutely an lnbits address that I do not use. Look at starting on January 16th. https://nostr.band/npub18ams6ewn5aj2n3wt2qawzglx9mr4nzksxhvrdc4gzrecw7n5tvjqctp424?edits

Anigma and nostr.com do this automatically when you login

i've never used anigma, but i have used metadata.nostr.com many times to set my profile data many times. okay i have a huge confused right now.

Example when i open nostr.com

Wow. Okay. I have some testing to do. And if this turns out to be just metadata.nostr.com doing this. Then I am 1) never going to recommend people go here to update their profile data and 2) send you some sats.

Doesnt seems like metadata.nostr.com is doing that, maybe you should reset your key manager permissions and just manually approve every signing until you're satisfied that its not adding LUD06

I think any client that lets you update your metadata without letting you select your preferred relay, fetching it and actually waiting for EOSE and showing you what the change will be is asking for trouble.

i do recall one day i did use nostr.com in recent times and i remember thinking oh cool, they support nip-07 sign in now. i signed in, poked around, but didn't do anything and i haven't been back to that site since that day. i will test. thank you again.

Sorry to hear this man! But if you do make another pub key; we will follow you 🤙

I’d like some cold wallet integration or Yubikey for the private key to be honest.

#[0]

There's no way around this unless you tie the key or the social graph to some other kind of 2FA or 3FA with an email or a phone number or another key (??) or X.

Sorry to hear. Over time I think there needs to be improved approaches to security. We must wrestle intimately with problems in order to understand them properly, which takes time and consideration. The approach to log in with a single private key will cause some acxounts to be compromized over time.

We should have a master key that lets us change our private key, or to deactivate our account and link to a new one. The master key would not be exposed until we use it. Its usefulness would depend on how secure the master key is.

so maybe a leaked via Amethyst or Daisy - can anyone confirm - currently I have a test ac on Amethyst - created key securely and entered by hand into Amethyst on android - downloaded via playstore on smasung galaxy phone

#[1] perhaps try sticking to 1 client for a week, see if anything changes, then add another client step by step to root our the culprit if it's a client misbehaving?

i think i've figured out what it happening. nostr.com automatically overwrites your lud06 with an lnbits wallet if you sign into it.

Happened to me too, lost my whole Follow lis.. I assume it has something todo with me fucking around with bunch of different clients. Luckily Snort has Follow All button, so I just easily refollow everyone.

We need a better way of managing keys other than typing it into a textfield

Absolutely.

This happened to me some time ago. From profile data reverts to old data. I noticed that it was a relay that didn't receive the update msg and it was in my list of relays in the client.

In your case, it could be some client or relay that has old information or some client with a bug that you sent to relays that you didn't add.

"I have over 3K followers and have worked really hard at that. I would have to have to start over. I really don't want to do that. It would essentially erase the last 6 weeks of doing nothing but living, breathing, and sleeping my desktop and phone.

Feeling lots of emotions right now."

we are learning so much. i almost dismissed the DID project as unnecessary over complication and corporatism pushing into web3. but i already seen a few problems unfolding on nostr real time, that makes me wish for some of that over complication.