Spec wise, I'm thinking either NIP4 for each password, or maybe a NIP51 encrypted list of all passwords.

It would be best for the client to be cross platform, desktop, android, ios. No need for app stores, sideloading is good enough (at least for Android, dunno / don't care about ios myself)

Maybe the NIP4 encryption should be ontop of a password encryption, kinda like a 2fa, the client remembers the private key, but always requires the password to fully decrypt. But maybe a 13th word passphrase works better.

Reply to this note

Please Login to reply.

Discussion

Yeah, agreed about the importance of having another secret on top of the nsec to prevent unauthorized clients from decrypting these.

#[4]​ in 5 days

A fun way to pay out the bounty would be to put the 2.1 mil sats onchain in a new wallet, put it into the password manager, announce that this encrypted event is holding keys with sats, and if it's not cracked within a week/month, the bounty gets paid.