rodbishop on Nostr: I think I just worked out a new signing workflow. We can approximate an offline ...
I think I just worked out a new signing workflow.
We can approximate an offline signer using an NFC card that holds an nsec.
Design a nsecbunker, and delegate signing to the bunker, but populate the bunker with a transient nsec, similar to Amethyst transient login.
Client asks bunker for signature. Bunker requests NFC tap in order to get the nsec. On tap, bunker applies the password, signs the event, and then forgets the nsec.
Required to trust the bunker software, but if the bunker gets hacked, or device gets compromised, it does not possess the key.
Thoughts?
Published at
2024-10-21 05:29:14Event JSON
{
"id": "47e183319872f5c83055ce5520c1166624092fc1d25751166560d8380c9f17df",
"pubkey": "1bda7e1f7396bda2d1ef99033da8fd2dc362810790df9be62f591038bb97c4d9",
"created_at": 1729488554,
"kind": 1,
"tags": [],
"content": "I think I just worked out a new signing workflow.\n\nWe can approximate an offline signer using an NFC card that holds an nsec.\n\nDesign a nsecbunker, and delegate signing to the bunker, but populate the bunker with a transient nsec, similar to Amethyst transient login.\n\nClient asks bunker for signature. Bunker requests NFC tap in order to get the nsec. On tap, bunker applies the password, signs the event, and then forgets the nsec.\n\nRequired to trust the bunker software, but if the bunker gets hacked, or device gets compromised, it does not possess the key.\n\nThoughts?",
"sig": "59b63272a976eeeeec253591d99f025585a5ee82405d075becb0b5a34bca93f06f06199b260b7e253393a5bd987e4a1f30d5a719dc987fb0e7175b974e752742"
}