Your noob friends don't need to backup seed phrases or nsec anymore. Just login to #wisp with Google and everything works without any setup or backups Haters will say pennies might get rugged and that their self hosted setups are more secure than Google image

Replies (54)

Default avatar
nicodemus 1 week ago
This almost feels like the beginnings of an Embrace Extend Extinguish operation. Whatever, nostr will be fine. Maybe more fragmented, but fine.
Hofer99's avatar
Hofer99 1 week ago
Just log in with google bro. Do no evil.
the wallet private key being derived from the nsec is actually fucking cool and peak nostr UX. now if we can figure out how to not use the Breez SDK and be gated behind an API key, id be 100% down for this. do i need to have my toaster take a look?
JackTheMimic's avatar
JackTheMimic 1 week ago
The Nsec that you have to Raw dog into your app? Hmm sounds like a nice rug in the future. Congrats on your scam.
Default avatar
Entropic 1 week ago
Trying to keep away from google as much as possible. Logging in with google is a bit spyware friendly no?
Any self respecting individual would use SSO as a means to get into Nostr, figure out wtf they are doing and then scale from there. It's insanely overwhelming to everyday people who use SSO and don't send instant money over the Internet. Biggest problem here is the learning curve. After they pass that point, they can easily use more complex clients, nos2x, apps, cashus, whatever the next thing is
JackTheMimic's avatar
JackTheMimic 1 week ago
My self-hosted setup IS more secure than Google's, I have brute forced my wife's password on Google by having the confirmation route to my email with auto captcha. Google is not a serious company. I was trying to be helpful with feedback but had to delete Wisp like 2 weeks ago. There's making Nostr simple and then there's recreating Primal.
JackTheMimic's avatar
JackTheMimic 1 week ago
I haven't ever leaked millions of people's personal data, or sold it to 3rd parties. It's 2-0, me.
If you move to a different country, Google locks you out of your account until you provide a phone number for "verification". It then accepts that arbitrary phone number as yours, without any further steps or conditions.
JackTheMimic's avatar
JackTheMimic 1 week ago
This is the same argument as "I'm sure central banks aren't as serious as an autist working on bitcoin." Just because you can trick people into a centralized system doesn't mean you are more serious, fucking obviously. Credentialism is weak sauce.
JackTheMimic's avatar
JackTheMimic 1 week ago
And banks can provide better security to a normie than them holding bitcoin. Welp, I guess we should never try to bridge the gap. We should never make more intuitive UI or hardware to hold keys with easy UX. Nope, just hand our sovereignty to Google, and the Fed. image
Well, I updated Wisp…but I need to login again. But I don’t have a Google account nor do I copy-paste my nsec there. I feel like a discriminated normie now. Do I need to create a new account? πŸ€ͺ
nix's avatar
nix 6 days ago
I had to work really hard to see the upside in using Google to sign into nostr. Feels like it taints everything. I could never have coded such a solution.
nix's avatar
nix 6 days ago
The only upside I could see is it could make nostr more accessible for normies that need it.
FunkyPopTart's avatar
FunkyPopTart 6 days ago
Why did you remove the ability to use remote signers? It should have stayed for those with that security in mind.
At the end I can understand the Google choice, it can be a good trojan horse, but removing the local signer option seems nonsense to me. If you want to smooth the UX as much as possible and remove any unusual stuff, you can simply bury it behind an "advanced" option. Of course you know that, so can you elaborate on your decision? I'm curious.
1. Who has noob friends anyway? 2. And even if you do: Let the noobs do it that way. 3. But who's going to tell those people about your app? 4. Well, not me, because I'm using a different one now.
You can solve this dilemma in one easy step... uninstall and never look back, as you seek out other clients that don't pull subversive bullshit like this.
Why is that Digit? I haven't seen them do anything malicious. I've only seen them push a bad update with removing the remote signer feature.
Well, to be fair you didn't pick a great example, you might not like Amethyst for its feature set, but it is very good from an architectural point of view. Anyway here we are not talking about features or the style of the app, but about a login/sign method used by a significant portion of Nostr users who span various user categories.
↑