But is it good in terms of security? I don’t want a vpn stealing my nsec 😱😱

Reply to this note

Please Login to reply.

Discussion

That’s not how it works. VPN has nothing to do with your nsec. Use an extension or signer app. Don’t plug into random new nostr clients

Well everything goes through the vpn, including your loggin credentials to any site, that’s why I turn it off while logging in.

There are no credentials on nostr. You are not authenticating to any server. You sign an event and send it to a relay. We use cryptographic signatures to do this.

I know that, I said “any site”.

I also know that, but that signature leaves your device through your vpn.

The private key cannot be derived from your signature. The signature is stored locally in a client or browser extension or another signer app.

Sorry but I’m not going to explain further. If you truly want to know how it works, search engines are your friend. Look up how nostr signing works and look into cryptographic signatures.

Thanks but I don’t need to go that deep to understand that when a VPN is on everything goes through it. I appreciate it though.

“I don’t know how it works but I’m going to ignore how it actually works”

Ok…

Don’t worry you’re a genius you can sleep well tonight.

Despite all traffic going through the VPN, your nsec never gets transmitted, so even a malicious VPN could not steal your nsec.

Your nsec never leaves your device. You only ever send proof of ownership of the nsec, never the nsec itself.

ivpn is what i recommend for every reason you can think of

https://github.com/ivpn/android-app

I’ll check it out, thanks