@jack, what if the blockchain could optionally enforce a requirement that your transaction is signed with your Nostr key? Even with a vuln like ColdCard saw, funds couldn’t move without your nsec. We’d need a BIP but it seems wise to me. This feels like something @Spiral could influence.
We’d have identity and money bound at the script level further improving security and control. @Bitkey hw could also securely generate (or import) and hold your nsec file and link it to the phone app.
@Bitkey would also be an authorized signer in a BitKey wallet implementation so my transactions would either both be signed by me or one by me and one by you.
I think of this like DKIM or TXT DNS records. Or TLS requiring not just a key pair but signed by a trusted cert authority. Similar pattern only using Nostr.
Jim Wilson
jimwilson@nostr.com
npub1pda9...qhek
Technologist
Obviously big news with the Coldcard vuln being exploited. I hope by some miracle this can all get recovered and prosecuted and it can be determined who owned which wallets.
I’ve been a fan of @Bitkey ‘s implementation and wouldn’t leave any real wealth on a single signed wallet even if offline and air gapped.
I do think it would be nice to give the option for the phone key to be a BIP-39 seed/passphrase but @jack and team probably did the math and between friction of the ux and security decided against it. But I’d still like the option as perhaps an “advanced” setup.