TOO MUCH CONCERN OVER LACK OF KEY ROTATION. NOT ENOUGH FOCUS ON HARDWARE SIGNERS AND MULTISIG.

Replies (52)

If someone wants to modify the #Signet firmware, it already stores keys/passwords/secrets in hardware. It's all #OpenSource. No permission needed to make the change.
ODELL's avatar ODELL
TOO MUCH CONCERN OVER LACK OF KEY ROTATION. NOT ENOUGH FOCUS ON HARDWARE SIGNERS AND MULTISIG.
View quoted note →
Key revocation and rotation is a solvable problem and is ultimately about authentication, regardless if a key is ever compromised! How do you know who is who? Do you remember their npub? Where do you save the name you have for their npub? Right now it is all just a list of pubkeys in a follow list (mostly).
ODELL's avatar ODELL
TOO MUCH CONCERN OVER LACK OF KEY ROTATION. NOT ENOUGH FOCUS ON HARDWARE SIGNERS AND MULTISIG.
View quoted note →
BTC Freedom's avatar
BTC Freedom 1 year ago
Yes, we need more focus on hardware signers and multisig. Time better spent 🫡
Hardware signer are cool but unfortunately have poor scalability for the masses (cost, shipping logistic, mobile usage). I would aim for multisign/Frost solutions.
renato's avatar
renato 1 year ago
it is a first aproach after all
TapSigner /Satchips are good for the masses IMO. Cheap and mobile compatible. Screens are a bit of an overkilling feature and necessary only for bigger amounts. Basically when you move your long term savings, with a private key that you will use only few times a year
I know It exists. And it's cool. But do you think that signing every event with this process is doable for the operativity of a normal user? No way. The easy solution is FROST bunkers.
bjorn's avatar
bjorn 10 months ago
No normal person wants to use a HWW or multisig to use nostr
ODELL's avatar ODELL
TOO MUCH CONCERN OVER LACK OF KEY ROTATION. NOT ENOUGH FOCUS ON HARDWARE SIGNERS AND MULTISIG.
View quoted note →
the frost2x extension repo (forked from nos2x) includes everything you need to setup a demo and dev environment it includes the extension, a second test node, and an ephemeral test relay as well just updated the README to be actually useful for setting up a demo, let me know what you think:
we have a web extension and desktop app, with plans for a mobile app and self-hosted server apps as well