"we can't, I repeat, can not, take away the consequences of lost (or worse, stolen) keys as such." Here is a system, functional and usable today, that greatly limits the consequences of a lost or stolen key from the time the rightful owner replaces the lost / stolen key with a new one.๐Ÿ‘‡ Can you explain how your claim is consistent with the actual existence of this system? Are there any flaws in this system that make it non-functional in your opinion? If so, can you or anyone else point out these flaws with some degree of specificity?
inkan's avatar inkan
The way it usually goes, your online identity is your private key. If the key is compromised, there goes your identity. Inkan fixes that. You keep a master key in cold storage and a signing key for everyday use. If the signing key ever leaks or gets lost, the master revokes it and delegates to a new one. Same identity, same followers, fresh signing key. If you'd like to take a look at the prototype: https://www.inkan.cc. Log in with your NIP-07 extension and say hi to the test identities already walking around. Or make one of your own.
View quoted note →

Replies (1)

Constant's avatar
Constant 5 days ago
from this perspective, you basically moved the problem; the main key can still be compromized. So in terms of the 2nd of the 3 things, it does not change all that much, all your system does is alter things in the first and second. So allowing a (main)key to remain in cold storage is a great risk reducer, though it changes the dynamic in how one moves forward, it makes consequences asymetrical. You introduce these sub-keys, and there the consequences are reduced and the ability to move foward smoothly is increased; at the same time the system's assumptions make a situation where a mainkey gets compromized worse. I.e. you introdue the moat for defensive asymetry, which work against you the moment your fortress has been captured, because you gave the attacker an automated way to divert your audience to their domain. The thing is though....this runs under the assumption that your system gets normalized, whilst it fundamentally changes Nostr. All the sudden the key=identity assumption breaks and every client has to run this logic that handles these subkey proxies etc. I.e. your system ''works'' if i run your specific client that can make sense of this all. Now i don't think any of this is all bad, and there is a reason i point people towards your stuff, and i do think you deserve more attention. I think your system has merit even without addopting the system's logic outright; as a ''formal'' indicator for what i think should ultimately be an "informal" process of social migration of keypairs, it could add value. At the same time High-risk profiles (like for instance the president of a country), could depend on the formal system logic to make transition more immeadiate. By which i mean: the convention of ''When following the president/important people, i* should be using these special clients that run these key-rotation schemes" * With "i", i mean people like journalists, or perhaps other officials, or other formal structures all of which for whom it is relevant to be made aware of a migration in the immediate term otherwise it could result in damage of some kind. If your idea is that we can just fundamentally change how Nostr works by adding this proxy-key logic, i want you to sit for a minute and reflect on what that actually implies and touches; at that stage you might as well start a new protocol from scratch all together, but then you will also quickly find that you no longer can claim to be " The simplest open protocol ''. In any event, if you lose your main key, your only option still is to cry regardless
โ†‘