They don't pass the key to the website. They sign the transaction and present the signed transaction to be broadcasted. It works exactly the same way as a Bitcoin wallet works. If you've ever used a Coldcard, Ledger, Trezor, etc.
Discussion
So, we need cold storage/hardware solutions for nostr nsecs. Why provide the private key to alby? just for convenience? Isn't the risk the same?
we have them... you can get one from the lnbits shop 😉
Also what I was wondering 🙂I figure it’s about trust. Nos2x probably will be safest 😂
