I might have compromised this nsec. At least, probably exposed. I don’t expect someone to try and abuse my account, if the key is ever even seen by anyone, but just for good measure, I’m delegating my “Boston ninja” profile below as a backup. If I post from there and say that my primary account is done, then trust it. Please toss that account a follow, if you don’t mind 🙏 Careful with that copy/paste, kids… Some hashtags and I’ll bookmark this note to make it easier to find if I need it in the future. And if anyone has suggestions, I’m all ears. #grownostr #plebchain #bostonwine #introductions View quoted note →

Replies (27)

Great idea. I’m planning to keep using this one for now, and just delegating boston2 in case I start seeing abuse here. It would take some effort to find my nsec, but since I know it’s “out there” I just want to get ahead of any nonsense 🫡
jared's avatar
jared 1 year ago
This is why we need a kind for “burn notices” for when nsec is compromised and include a referral to the new npub. Use time and web of trust to resolve competing referrals since attackers with nsec could issue malicious referrals. Once time and web of trust is sufficient (judged by client developers) the client can auto follow the new npub and flag anything signed by the compromised nsec. Just my $.02
I used this command: nohup time ./nostril --mine-pubkey --pow 32 There’s Rana by @negrunch : This method is slower, but it lets you specify a hex prefix which isnt as useful anymore since we use npubs. I’ve never used this website but if you do make sure your computer is offline and you close the browser entirely for a few minutes after mining before bringing it back online:
Thanks brother. I actually do that too. Issue was I had (long ago) saved it somewhere and was doing some cleanup of various npubs, and I copied it to see what profile it was, without realizing it was a private key, and then (briefly) left it somewhere I shouldn’t have. It may never become an issue, but just getting ahead of it to be on the safe side
Damn dude, thank you! These are all very helpful - will test out tonight when I’m back at my computer. Re: nostr.rest and closing the browser, is that to get any key material out of short term memory before it goes online and could share it by mistake?
hello and welcome to nostr. if you like little children, click here: #loli. this is automated message by nostr admin. please do not reply to this message.