Geektoshi's avatar
Geektoshi
geek@getalby.com
npub1m2jp...3wgu
If you don't believe it or don't get it, I don't have the time to try to convince you, sorry.
Geektoshi's avatar
Geek 5 months ago
What if your remote signer could tell you if a relay connection is trustworthy? What if any client could? Soon TM ๐Ÿ˜Ž
Geektoshi's avatar
Geek 5 months ago
Starting work on Signet 1.7.0 today which will introduce NIP-49 support (ncryptsec). AES-GCM encryption will still be available and existing keys can be easily migrated with a single key press, but NIP-49 (XChaCha20-Poly1305) will be the recommended option moving forward. AES-GCM will be deprecated in the 2.x.x series but that is months away so plenty of time to migrate. It will also add key exporting (plain nsec and ncryptsec). Signet will default to LOG_N=16 for the time being but will provide user configuration in a future release if you want stronger encryption. The NIP-49 spec allows up to LOG_N=21 but the memory requirements are higher than most users will want to spend (64mb to decrypt LOG_N=16, 3.2gb to decrypt LOG_N=21) for a signer. This is probably above most people's heads but I'll do a long form article sometime near release, but there's plenty of documentation around on NIP-49 and its encryption choices. Maybe the good folks at @Nostr Compass can add some NIP-49 info to their newsletter in the mean time ๐Ÿ˜Ž
Geektoshi's avatar
Geek 5 months ago
I'm a huge fan of NIP-85 Trusted Assertions and WoT. Would love to have a system in place to establish trusted relays as well due to my work on remote signers, but NIP-85 does not handle this. While the below could really just be an extension of that NIP, here's a stab at it. Comments are welcome, it could use some tweaking for sure. Tagging the maestro @Vitor Pamplona
โ†‘