Not really. The enclave dies, everything dies. If the enclave generates an nsec that is to never leave the enclave, then that nsec only lives as long as that physical machine lives, assuming you pay your monthly bills. What it does help with is management of a key you accept will be know by someone at the company who may in future not be at the company. But you still have to accept that, so the core problem remains.

Replies (1)

Niel Liesmons's avatar
Niel Liesmons 6 months ago
- You can have multiple enclaves with the same nsec. Generated and sent to them by another enclave (for example) - You can play with conditional export of the nsec - You can verify if an nsec was exported by someone To me, those are #goodenough bulding blocks. And again, solution is needed regardless.