Avatar
Sebastix
06639a386c9c1014217622ccbcf40908c4f1a0c33e23f8d6d68f4abf655f8f71
Web of Trust foundation board member | Kubo.watch developer | Nostr-PHP library maintainer https://github.com/nostrver-se/nostr-php | OpenSats grantee | Check all my Nostr contributions and services on https://nostrver.se | Solopreneur as a creative / fullstack webdeveloper from πŸ‡³πŸ‡± #PHP #Drupal #Javascript #Vuejs #InteractionDesign | What we need more #FOSS #Privacy #Selfhosting #DigitalWellbeing #Family | Hobbies #Cycling #Gravel #HondaCivic #Circuit
Replying to Avatar Dr. Hax

I read Proton's take on Passkeys. I have thoughts...

https://proton.me/blog/big-tech-passkey

I have stayed away from the closed source implementations being pushed by big tech companies like #Apple & #Google. I have also steered clear of all #software implementations. So if was nice to be informed on what a shit show it is over there. Not because I want to validate my prior choices (although that does feel good), but so I can help advise people who have different desires than I have.

For me, this is what I want, and why:

1. Completely #OpenSource solution. I've had the rug pulled out from under me too many times to put up with another "sunset" after just a few years.

2. A #hardware implementation. I can use it on a compromised device and still be safe (sans that one login session). This is not true with pure software solutions, including those that use a secure element.

3. Never sync it to any #cloud, let alone someone else's cloud! I understand it's e2ee, but it's more risk than I want to take. I could go into the threats, but I'm trying to be brief here

4. Prefer the ability to #backup and restore, although this is not strictly necessary. It's easy enough to just register two devices to services and never have the secrets leave those devices. But it's more cumbersome than having two devices that are clones of one another. Only have to register one key, and can still recover easily if it's lost or destroyed

I'll admit that this is a high bar. It's still what I want though, and I'm only willing to compromise on that last point.

You might be wondering if anything even exists right now that can meet my demands. I'm happy to say that there is: the Trezor Model T.

https://trezor.io/trezor-model-t

Sure, it can hold the #keys to your #bitcoin, a feature which you may or may not care about, but perhaps more importantly it actually meets all of the requirements for #Passkeys / #FIDO2 / #u2f / whatever you want to call it!

Full disclosure: I do not get any compensation from #Trezor for anything.

#security #cryptography #FreedomTech

These are some interesting thoughts, thanks.

Replying to Avatar elidy

nostr:npub1w0rthyjyp2f5gful0gm2500pwyxfrx93a85289xdz0sd6hyef33sh2cu4x looks great. I was testing its subscription options and it wiped my profile. Is there a tool to get followers back?

nostr:npub1l2vyh47mk2p0qlsku7hg0vn29faehy9hy34ygaclpn66ukqp3afqutajft

nostr:npub1l2vyh47mk2p0qlsku7hg0vn29faehy9hy34ygaclpn66ukqp3afqutajft Did the 10002 event took the mastery πŸ‘ŠπŸ» here by publishing a new kind 0? πŸ€“πŸ˜œ

Thanks for this great recommondation nostr:npub1asuq0pxedwfagpqkdf4lrfmcyfaffgptmayel9947j8krad3x58srs20ap πŸ™πŸ’œ

nostr:note17hp4cggn4v8h9q42v6q73358dsaurjvmyt7927c6hzkrqnlwl59scaqkff

GM!

Some very aggressive cold got me this night 🀧πŸ₯ΆπŸ€§

Replying to Avatar Sebastix

The #LNBits Zap Lamp works! In this video I've set the npub of nostr:npub12hcytyr8fumy3axde8wgeced523gyp6v6zczqktwuqeaztfc2xzsz3rdp4 to test it out. I just changed the npub to my own, so the lamp is ready for some test zaps ;)

I will give the lamp a nice place in my office coming week. Maybe I could set up a livestream with nostr:npub1eaz6dwsnvwkha5sn5puwwyxjgy26uusundrm684lg3vw4ma5c2jsqarcgz so you can realtime zap and see the lamp flash πŸ€“

The #LNBits Zap Lamp works! In this video I've set the npub of nostr:npub12hcytyr8fumy3axde8wgeced523gyp6v6zczqktwuqeaztfc2xzsz3rdp4 to test it out. I just changed the npub to my own, so the lamp is ready for some test zaps ;)

I will give the lamp a nice place in my office coming week. Maybe I could set up a livestream with nostr:npub1eaz6dwsnvwkha5sn5puwwyxjgy26uusundrm684lg3vw4ma5c2jsqarcgz so you can realtime zap and see the lamp flash πŸ€“