That’s what I figured. Why would a reputable site ask for that?

Reply to this note

Please Login to reply.

Discussion

I use Nostore!

Because it’s still early. It was a common way of making it easy to sign in before Alby and other extensions became available. Thankfully it’s becoming less common.

#[4]​ may I suggest that you guys remove it from badges.page?

Extensions are not available everywhere. I encourage people to use an extension. Want to make it easy for as many people as possible to use the site.

Fair enough.

Security > convenience imo

The early ones building are teaching consumers what habits to build. Compromising nsec shouldn’t be a habit we enable

the login form is literally telling you to use an extension instead of nsec to try to build that habit.

Not trying to call you out homie, I’m just saying giving a customer an input field for their nsec isn’t going to do us well down the road 🙏🏼

I'm not pissed but got that comment a lot today, agree that UX can be improved and always happy to take patches https://github.com/verbiricha/badges one thing I'm going to do for sure is only ask for npub and only require nsec if you need to sign something and ext is not available

That would be an improvement.

Easy ≠ better. Especially as leaders in the space

Not technical enough to offer commits. But would love to help in other ways if I can.

this is great feedback, has taught me a lot about best UX for nsec management. Going to vastly improve it.

What does a password manager do except dump your nsec for you?

in other words… a nip 7 extension doesn’t just automate the dumping of your nsec, it generates the sig on the clients behalf and just passes the one sig it needs for that event.

I agree. The extension is the way to go.

Entering nsec in plaintext form on a website 🚫

Yeah. The password manager comment wasn’t aimed at using your nsec, just storing it somewhere safe.

Nip-07 extensions are the way to go.