Why Nostr? What is Njump?
2024-08-16 11:04:53
in reply to

matt on Nostr: The main problem being what it already is for Nostr apps: getting completely rekt if ...

The main problem being what it already is for Nostr apps: getting completely rekt if that key gets compromised. Nostr has to fundamentally change and mature before I'll ever use it for more than a low value social media use case.

I only enter my password manager password in one place. Entering it into a bunch of different apps creates the same problem of using the same password everywhere. You'd need to create a different nsec for every app to avoid this, which is fine, but that isn't what most people will do. They'll just paste that sucker into anything that asks and eventually get rekt everywhere just like people do now. The main difference is that there is no recovery under the current model. You can't just contact Nostr customer support and prove your identity to reset your nsec and take back control of everything you used the key for. It's gone forever. That's why I think it's more dangerous than the current legacy model for the average person. It's also an instant take over. Whoever has the key can access any Nostr app instantly, without even knowing which service the owner uses. Currently, an attacker would need to figure out which services I use to access them if I use the same password everywhere, and that takes resources. Nostr is just one protocol.

Things need to get better before more people are encouraged to use Nostr for everything.
Author Public Key
npub1l6scds4yv7xmcsmhqnhdy9sggm520q09lvts2m5mkvecgr2mmmeqsuj5rc