just doing signing in a sandboxed env with no networking is just defensive programming. it's also just practical for us because sending the nsec from native code into a js browser extension just seems wrong.
Login to reply
Replies (1)
yeah. I expect browser extensions to be sandboxed just as well as websites, though.