Global Feed Post Login
Replying to Avatar ChipTuner

Could also have a client do that too. Take the event address and put it into a client I like.

I think this could really get into scope creep for the signer, then the signer just becomes another insecure client. Clients and signers NEED to have clear separation of security concerns. Signing code should be physically isolated from network code.

Avatar
ChipTuner 7mo ago

Main reason I don't really agree with nip46 and have aired my concerns in the past. NVault will have separate processes and remote agents for handling signing. And someday work with HWS like the one nostr:npub12262qa4uhw7u8gdwlgmntqtv7aye8vdcmvszkqwgs0zchel6mz7s6cgrkj is making :)

Reply to this note

Please Login to reply.

Discussion

No replies yet.