Key thing that needs to be addressed is to somehow be able to auth without providing the same pubkey to every service to prevent trivial links between accounts.

Should be easy to do, but important to do from early on with something like Nostr login to allow aliasing!

Reply to this note

Please Login to reply.

Discussion

Agreed we need better key management. Exposure of a private key means loss of everything now.

PS tried to zap you but got an error message. Your btxpay server might be down.

Yeah, down for maintenance 😢

What if we had derived keys from the private keys and each derived key is an "account" or "profile" where you could also have more derived keys? Each derived key or tree of keys cannot be traces or linked back fk the master privare key. Almost like how BIP-85 works.