An attacker can send messages from my account before I even know that my key is compromised.
When my account is compromised, both the attacker and I can post from my account, as long as your idea isn't implemented.
In such a scenario I will post that my account is compromised and provide *evidence* via other social media accounts. The attacker can't do that.
I could also prepare in advance by setting up 1-2 backup nostr accounts that only I have access to, which are unlikely to be compromised at the same time.
Your idea would prevent me from posting from my account, and that is very dangerous.
Do you really think attackers don't already have this tooling? It's already coded. It's quite literally 20-30 lines of code to delete all your events from all relays.
Why would all relays support such a tool?
They already. Most of them.
I see. I guess we have to live with bad security implementations then.
One solution is that we prepare by creating one or several backup accounts and use them to verify our future account when the old is nuked.
Yep... A service like that can be useful.
Thanks for the heads up.👍
Thread collapsed
Thread collapsed
Thread collapsed
Thread collapsed
Thread collapsed
Thread collapsed