Replying to Avatar DataNostrum

Idea for account recovery, in case you lose your nsec or it gets compromised:

1. Right now, set up a "failover" nsec/npub pair. Store the information separately from your current nsec/npub pair, and publish the failover npub on #nostr.

2a. In case your current nsec gets compromised (i.e. someone else is also able to post from your account), switch to the failover nsec/npub and disavow the previous npub as compromised, pointing to the message that you published in 1.

2b. In case you lose your current nsec, locate and start using your failover nsec, and announce that you are migrating to the new npub.

In both cases, it would be beneficial if people were *already* following your failover npub.

Perhaps this logic could be integrated into #nostr directly, so that the failover npub can specified as part of the protocol, and that a client knows that when you follow someone you automatically follow their failover npub as well.

nostr:npub180cvv07tjdrrgpa0j7j7tmnyl2yr6yr7l8j4s3evf6u64th6gkwsyjh6w6 #nostrdev #asknostr

Avatar
Azz 2y ago

What if an impersonator makes a duplicate account and says that it is your failover account?

Reply to this note

Please Login to reply.

Discussion

Avatar
DataNostrum 2y ago

That's why you have to announce your failover npub on your current account, which an impersonator can't do.

Thread collapsed