It’s amazing to witness that we don’t have any key management solution on #nostr ! Can someone just start compromising our keys and post them publicly on here, so devs will start thinking about something that make sense to start think about !

Reply to this note

Please Login to reply.

Discussion

Soon

test-auth.shock.network

👀

Tell us more

Apps will be able to paste in a widget so no browser extensions needed, allowing for an enterprise class UX and management tools

Update for it coming to ShockWallet next week

Interesting! I also meant something that will be able to change the current NSECs for example! If it’s compromised or when it’s compromised.

Yea this will just help have them not get compromised in the first place, there's no graceful way to recover from that... Gotta repoint everyone

How it is different than Amber or any other extension ?

By not being an extension, it's a software remote signer, management dashboard, and widget any developer can embed

Pablo made some proposal some time ago where you would "save" and announce some npubs for the future, and when you would get compromised you could "activate" one of those npubs as the new one. Something like that if I recall it.

Yeah I remember that.

Yup, NIP-41. PR is still open but needs more support from devs. I think addressing moving to another npub in a non-catastrophic way is still one of the big hurdles to be solved

- Create a vulnerable webpage that sends the private key to attacker

- Landing page should be a game nostr users can play using their nsec

- Gamers are rewarded with ecash

I am sure you will get at least 100 private keys in one day with this simple social engineering and a webpage.