Avatar
Gian Lazzarini
1f55c94bf08a2622869c89c18e614a05eec58b350f22e8ef99803a93285a37d8
backup account gianlazzarini@nsec.app npub1jarngawpw0ufy792demxf3j7ljad440ypmazmqqpshpqws3fpc5swmmt4d

Apparently #Reddit banned tons of subreddits that may be seen as “unsavory” to investors. Then unbanned them and said “whoopsie”. All the better reason to get off onto the #fediverse with #lemmy etc.

https://www.reddit.com/r/BannedSubs

Oh this is great… I usually remove that myself but forgot this time.

Yeah I know there are options out there, but for example I don’t think there are any nostr hardware signers that can be used with iOS. For this to receive more mainstream adoption we’ll need development here.

At this point in development I think that may be the reasonable approach. However going forward when people invest large amounts of energy into a nostr identity, we must adopt better private key security practices, such as hardware wallets do for “crypto”. However this may resign this platform for a small subset until the public can become educated on the subject, and development has been furthered on the platform.

While I really like #nostr the whole #fediverse via #activitypub #mastodon and the likes seems to already be usable and “good”. While nostr may be reaching for greatness. Don’t let great be the enemy of the good. https://urbanists.video/w/n7xyeV1kbW8mUKr4ncchhs

After trying for an iOS and external #nostr signer I’ve resolved to continuing for now to use the existing clients that unfortunately rely on pasting in your private key. I think nostr is really promising and I don’t want to miss out on the developments.

After a fair bit of research, it seems that there's no acceptably secure native iOS nostr client as of Jan 2025. All that I found expect you to paste in your private key 🤯. I find this unacceptable, and going forward intend to only use nostr clients that support external signers.

Again, looking at iOS this further limits the options down to #nsecapp and #nostore. Between the two nostore only works on iOS, whereas nsecapp is cross-platform.

Having a background in app development I don't see any good justifications for a native nostr client... A #PWA client is the ideal solution for most, as far as I'm concerned. It's the most free and open, cross-platform app distribution platform, the internet.

Also in part from, pressures from the EU and such, apple has reluctantly caught up sufficiently with their iOS PWA support, critically by adding web push notification support (however this seems to have its own privacy concerns but that's an issue for a separate day).

So with that, I think that the most free, independent, cross-platform, secure approach at this time is to use the #nip46 based https://nsec.app PWA and one of its supported clients such as #snort. Bonus points for self-hosting these for yourself and your community with something like #tailscale.

Replying to Avatar Five

[SatShoot](https://satshoot.com) Nsec-app login with "Bunker URL"

What do you guys use to secure your nsec? 🔐

https://cdn.satellite.earth/968f3f9eb1c9808f4c2cd2434ad8f17e4eff0d1916f0f6e98ec85838de338b14.mp4

#satshoot #nsecapp #nsecbunker #security

lgtm

Made a backup #nostr gianlazzarini@nsec.app as a backup. I like the service however I think it’s probably best to run it selfhosted on your own machine as you’re trusting the service to manage properly encrypting and storing your secret keys. TBH I just want a hardware wallet at this point. #nsecapp

Looks like a dedicated software #nostr signer may be one the options for maintaining private key #privacy. I’m looking into https://github.com/ursuscamp/nostore and https://use.nsec.app

I kind of consider this private/account already potentially compromised. Backup accounts may be a good idea…

Pasting your #nostr private key into clients to log in sure seems reckless and unsustainable if we care to actually invest in this platform. #security #pgp

How about the #openvibe client? I’ve made a #threads, #bluesky, and #mastodon account now in testing out #nostr clients. I like the idea of consolidating all of the budding networks into one place. Let’s see how this goes.

So far I’m getting the most “warm and fuzzies” from the nostr protocol.