🔑 Boost your account security with NIP-9999! 🎉
This proposal brings subordinate keys (nsub) and revocable delegation proofs to Nostr, delivering enhanced security and scalability for key management. 🌐check out the article,written by @SwBratcher View article →
Login to reply
Replies (12)
Ok I think I did that…
In the lower left corner of the app (on iOS) I pressed the comment button and added it there as well.
I see there are apparently 2 comments on the article now.
However in YakiHonne, when viewing the article, where / how should I see other comments? When I click the comment bubble it only slows me to write another comment
I’ll move this to a place that is better suited for discussion. Awaiting some advice as to where.
Right now deep storage of your nsec would be too inconvenient. With this NIP, it would become convenient as only delegate nsubs would be out in the world, treated as we treat nsecs now, and would be revocable.
I know there is an app to store it in, but that’s just trading one attack vector for another.
I wonder if there is a way to make your nsec only visible client side, so there is no way to extract it from the client itself.
Sort of how you can use a cloud storage app that has client side encryption so that the server maintainers don’t have access to your info.
Right now, my biggest worry, especially with most of the clients being open source, is that someone will figure out a way to gain access to a user’s nsec.
My vision on this, especially for high value brand accounts, would be a never-seen nsec on hardware, or a simple highly specialized and secure application, that's just used to sign nsub delegations and revocations.
Long press the comments button, and you’ll see all the comments.
Here’s the current draft of the idea in GitHub, where deeper discussion likely belongs… Needs both dev and UX feedback to clarify capability of protocol to handle the change, and the importance of the change for user security and adoption.
https://github.com/swbratcher/nips/blob/master/NSUB.md
Nice proposal. Keep up the good work
Subordinate keys 😱. What a great idea 💡 — This is a comment on: https://yakihonne.com/flash-news/nevent1qqsq246kv6y35haku9f26yqa5tj966eq8nn0mgh6anmk5ex4klwa5kqzyqsfsmac8em4m9k33r99e803pnndvylqadl9w69q7zcjkd7d4ssmxqcyqqqqqqggzd9m5
Thanks!
I must not be as smart as I thought LOL
Game-changer for Nostr security! NIP-9999 redefines key management with innovation and scalability!
These need cases match the existing intent of the NIP. But I was exploring the attack vectors, and there is too much vulnerability for this. Likely won’t work. And too much governance passed to the relay. I’m going to have to reapproach the solve, which is needed. But this may not be it and I’m stepping away from the NIP. I’m a noob on the protocol so sorry about my learning curve.