My feedback. I think the main issue is with double dipping on two separate narratives. With nsec bunker, you don’t get the benefits of the keys. It’s a reversion back to username and password. But you do get other benefits with that. So just pick one or the other. Presenting both just shows the annoyances / cons of both.

nostr:nevent1qqsrw4tgcsjg46q0j77v7vgq30qme9cnuj7t43agqcusza6ej2krs2spzpmhxue69uhkummnw3ezuamfdejsz9rhwden5te0wfjkccte9ehx7um5wghxyecpp4mhxue69uhkummn9ekx7mqpzfmhxue69uhk7enxvd5xz6tw9ec82cs23m699

Reply to this note

Please Login to reply.

Discussion

With this solution you actually get both benefits: you own the keys but you can use a safer and revocable login token that is "semi-custodial" (all signer need to collude to steal the nsec). Of course the user need to understand a new paradigm: keep the may nsec safe and just use the derivated token(s) to login or sign.