Aaaaaaaannnnd.....I just found my food in the microwave that I heated up 3 hours ago. The struggle is real.
Printing the case for my kid's #nerdminer Christmas present.

I don't think so. All users who have a fingerprint enrolled can see the secure partition. Any of (I think) 10 fingerprints gets you access to the secure side. They can be 10 different people. The only elevated privilege for admin is the fingerprint add. It's very simple. I'd bet it's hackable, but that's way out of my league.
I just got one of these Lexar F35 drives. It was about 30 bucks. It might do what you need. Some things:
- It does require Windows to set up, unless someone smarter than me can make it work in Wine. The app seems simple.
- Fingerprint programming is easy and fast.
- Users get assigned roles as admin or "other users." Admin can add and remove users. All get access to secured partition.
- The app lets you choose the size of the secured partition. I got a 64GB drive and it will partition all of it secure if you want.
- It unlocks the secure partition on Windows and Linux.
- I could NOT get it to unlock secured on Android phone (Pixel 8). Tried external powered hub, also.
- I abused it a little by yanking it during write, startup, etc. and it didn't lose anything.
If you want me to try anything else, let me know.
Found this in the yard.

Ah I see. I didn't realize it was that formal. Dang, biometrics is the way, then. Back to square one.
I keep thinking about this. You said the restoration device would be left with trusted friend(s). So let the friend do the verification. Two keys needed to restore the account. Perhaps two TOTP codes, generated by two yubikeys. The friend won't give their TOTP out if it's not the owner of the account. TOTP lets them verify the person remotely if needed. The account owner goes for their stashed key, friend gives it to them, owner TOTP goes in, friend TOTP goes in, account restored. Tie all these various codes to the account during initial setup.
I just ordered the Chillum for my kid to try. He's been in youth size Altra Lone Peaks, but they quit making them. Zero-drop kids shoes are tough to find.
Me, halfway to work when the battery runs out.
Oh I meant the USB drive. The phone doesn't need to show anything other than "Restore?"
I may get one to play with. Needs Windows for setup, though. π’
Is PIN entry not an option? Couple of buttons could be cheaper than biometrics.
Other than the price, it ticks all the boxes. 100 bucks is prohibitive, especially if you need multiple backups.
nostr:npub1gcxzte5zlkncx26j68ez60fzkvtkm9e0vrwdcvsjakxf9mu9qewqlfnj5z If I send a note and lose network connection for some reason, will the note broadcast automatically when the connection is restored?
I was seeing a note in #Amethyst but not in a web client. Selecting "Broadcast" manually in the app sent it right through. So do I have a setting to change, or is this supposed to be a manual event.
I know now to watch for the relays to appear next to the note. Took it for granted that I was connected before. Learning has occurred.
Checking some things here...I got a zap loaded for the first person to reply with a screen cap of my profile page showing the first couple of posts. #plebchain


