Exactly. Which is why it doesn't make sense for me to maintain all that signing code
Login to reply
Replies (1)
You don't remove a security feature because most users won't use it.
You make it optional, default to the simpler flow, and leave it there for the users who need it.
Unlike a password, you can't reset an nsec. If it's compromised, everything tied to that identity is gone permanently.