So I've been fascinated by Shamir's secret key sharing algorithm for several years, and I'm pretty convinced that self sovereign identity, while cool, is not actually the best option for decentralized social networks. Especially the incarnation of self-sovereign identity that relies on you keeping a secret, and also that secret must be stored on a computer.
Like instead fully custodial or non-custodial keys I would rather my friends and family being the ultimate authority on which key is mine. I would do this with my Bitcoin wallet and other keys but *especially* my Nostr key because Nostr is a social network, so the real value is in the social connections we have on here. So in the worst failure mode where all my friends and family betray me and steal my identity... my social network is already dead.
There was a group of folks who built a tool for breaking your key into shards and backing it up your peers on Secure Scuttlebutt several years back (https://darkcrystal.pw/). I've always wanted a version of it for Nostr and now that I'm a free agent I'm going to give it a shot. If you're interested in helping or trying it out when it's ready let me know in a reply or DM.
Login to reply
Replies (8)
WOT keys. Love it. Happy to help with non-dev things
Very cool 👀, please share as you go, interested to follow along
I'd try that!
Interesting concept.
Promenade by nostr:nprofile1qqsrhuxx8l9ex335q7he0f09aej04zpazpl0ne2cgukyawd24mayt8g2lcy6q and frostr by nostr:nprofile1qqsyy2wzruqsr27rhfzjx0shd6t4l20xwxa33fnj900hwf46y4z9l7gwlvtz8 and Austin might be helpful on the technical side. I like the idea of aligning key storage with existing trust relationships a lot.
Yes! Thanks for the reqs. I have played with both of them, I think frostr explictly has the key recovery feature but I couldn't get it to work. But I should go a level deeper on checking them out.
It is really fascinating: https://max.levch.in/post/724289457144070144/shamir-secret-sharing-its-3am-paul-the-head-of
Relatable. I've actually had this bug on a bank website before. They truncated my 20+ character password, I wonder if they were running Solaris somewhere in the background.