one is more secure than another in a very specific edge case that involves zero-days that would not be wasted on an nsec, I guess
Login to reply
Replies (1)
just doing signing in a sandboxed env with no networking is just defensive programming. it's also just practical for us because sending the nsec from native code into a js browser extension just seems wrong.