Avatar
Zio Mc
dc1be7fdba0c8a1bf9065cdee45c948d574e780f74894251e9c95d16432655b9
Nostr...this must be the place

OK you don't have to use browser in incognito mode or clean browser cache.

nostr:nprofile1qqs827g8dkd07zjvlhh60csytujgd3l9mz7x807xk3fewge7rwlukxgpz4mhxue69uhhyetvv9ujuerpd46hxtnfduhszrnhwden5te0dehhxtnvdakz7qgswaehxw309ahx7um5wghx6mmd9usjfpck can you confirm that if a use amber as remote signer, it keep a connection with relay.nsec.app waiting for some clients post a request, does it happen even when the phone is in sleep mode or soft sleep?

You're right but I see kagi has 10$/month unlimited searches, this could be a valid option.

Nip04 are direct messages, but all nostr users can see when, the sender and the receiver. Dm-reporter scan nostr and post all collected DM aggregated

Replying to Avatar hodlbod

**Security Update**

I've got some bad news for you guys. This morning, as I was adding error handling to flotilla, I discovered that Coracle has been sending user session objects to bugsnag when reporting errors.

Who is affected: Users who triggered an error in Coracle while signed in with their private key, since December 5th 2023.

What I've done:

- I immediately released a new version of Coracle, both to web and to zap.store

- I have deleted the affected apks from my releases

- I have deleted all my error data from bugsnag

- I have deleted my bugsnag project and rotated my api key, so lingering error reports will be dropped

- I have audited my code for use of the session object to ensure nothing else like this is happening

What you should do:

- If you're logged in with your private key, log out

- Hard refresh the page to ensure you have the latest version of Coracle

The bottom line is that if you signed in to Coracle with your private key, it has been shared with me and with bugsnag. In practical terms, your keys should still be secure, since they were sent over TLS, and have been deleted. But there is no guarantee I can offer that they are in fact gone.

I take my users' privacy seriously. My error reporting implementation doesn't record user IPs, it redacts identifying data, and it allows users to opt-out. I also warn the user when they attempt to enter an nsec into a text field. In this case, I simply screwed up, and I sincerely apologize. Reply to this note if you have any questions.

I remember someone proposed to unlock btc wallets with nsec nostr key.

Mmmm bad idea.