How much more secure you think it is to use this vs having your key in a well established client. Both devices are online all the time. Phones might even use secure enclave while the signer doesn't I guess 🤔

Replies (2)

It's essentially the same tradeoff as having a hot wallet vs cold storage when it comes to bitcoin. Is the wallet provider going to run off with your keys and damage his reputation forever? Unlikely, but what if they get hacked or compromised by a government? A device which is online all the time in the security of your home/office can't really be compared to some (probably) AWS hosted webserver just because both have an internet connection. One is entirely under your control, the other is not. Do you like responsibility in exchange for control? If so, it's for you, if not, you're going to prefer convenience.
Another thought. You have your nsec in a well established client. But nostr moves fast, what's well established now might be dead, obsolete, or broken and unused in 3 months as people tend to switch clients rapidly, esp on Desktop. What if the dev of said formerly well established client is salty and frustrated because ppl dropped his client in favor of the next thing the influencooors told them to use and stops working on it? What if the client never deletes your nsec? What if the dev goes rogue? What if the dev hands the server to someone less who has bad intentions?