Hard to get everyone to adopt key rotation yeah.. PGP is the only thing that sort-of has built-in rotation, but does it really? It's just a new key, and an expiry to force people to go find the new key.. Bitcoin doesn't have it at all.. Etc.
Cool that you tried tho, the complainers really have no grounds to stand on, other than "muh UX should be ez for muh normies like muh centralized platform" Even keybase.io, hardly got any traction. Showed how much people say they want something, and then they don't use it.
Login to reply
Replies (2)
Yeah, I agree. That’s why my last attempt at key rotation wasn’t about key rotation at all, but about identity continuation. And I think not everyone, but some people might use it, specially entities or "high value" accounts. As I see it they would work more like a kind of change.org campaign. "Hey, this is my new key, there you have some proofs (wot voting, secret revelation, any other proof) that this is me and not an impersonator"
I just want to point out again that we have a fully functioning key revocation and replacement system in Nostr. I've been using it every day for months now.
You can literally just head over to
and create an identity that can delegate signing authority to delegatee keys and revoke it when these keys are compromised.
This enables cold storage identities for Nostr. If you want to see one of these identities in action, here is an example:
And here is the draft NIP that goes along with the reference implementation:
View article →

Inkan
Inkan web client

Inkan
Inkan web client