Ross on Nostr: I confess I also don't know how it works in detail, perhaps it is possible to verify ...
I confess I also don't know how it works in detail, perhaps it is possible to verify with an air gap!? But even then it sounds terribly centralized to me. If it was me, I wouldn't use the PIN server verification for that reason. Just use a Bip39 passphrase and you can negate much of the risk of not having a secure element. I guess in the end it depends on ur threat model and the tradeoffs you are willing to make..
PV fren 🤙
Published at
2023-03-05 08:42:27Event JSON
{
"id": "b86210032f7ac28d0a4fabc2551fc82d4bee6879bb881f10bf64a43f9548c0f3",
"pubkey": "7ba14840967b301428dc7eb402687379ce854c4d6cafc35aa1fb76aca63cbe2b",
"created_at": 1678005747,
"kind": 1,
"tags": [
[
"e",
"55ae64d6df914023b8b568281d98d1b08b72e12c6462dc2f6c0f03fdcb36da2c"
],
[
"e",
"e982a85b521f7a563e9dc7e02e2a58e01bb725ed85387fa69e190e748b03f581"
],
[
"e",
"f22f1f93634717d95781a0f752e87e5d4bd1e38dc185d238c96a04016b5f7926"
],
[
"e",
"09d1dd46b83ea5dacf7966ba87234f28a973706aa2e0f04531b192712a151c70"
],
[
"e",
"d2b82df7eda4a357e9e68258d3d34184a70f758941ff39a0f16d1b6af79aeab6"
],
[
"p",
"644aa0bf6f56b8457bfb1fb159f32b318c9c504ec0d956c7314f2f3de2de8126"
],
[
"p",
"7ba14840967b301428dc7eb402687379ce854c4d6cafc35aa1fb76aca63cbe2b"
]
],
"content": "I confess I also don't know how it works in detail, perhaps it is possible to verify with an air gap!? But even then it sounds terribly centralized to me. If it was me, I wouldn't use the PIN server verification for that reason. Just use a Bip39 passphrase and you can negate much of the risk of not having a secure element. I guess in the end it depends on ur threat model and the tradeoffs you are willing to make..\nPV fren 🤙",
"sig": "5da1bede7cadb7d3beada41dcad4abe788fb5bcdd1ad4ebcda46dea4389faf9d479f178742eba2ccd2ab1df37c132269cc36723966c34c3b3701d2337fea8057"
}