Thread

Zero-JS Hypermedia Browser

Relays: 5
Replies: 67
Generated: 21:31:42
Login to reply

Replies (67)

This is gold .. one npub for communication and value .. can it show my Bitcoin balance right on my nostr profile :-) .. to make sure I flaunt my holdings ..
2025-10-18 20:00:40 from 1 relay(s) ↑ Parent Reply
The clients should remain dumb to this process to avoid a leak. The users should be deriving the nostr key from their master key that they have thoroughly backed up in steel plates. You can recover the child key as long as you have the master key back up and the index number attached to the child key. This is primarily a security feature that users must warp their heads around. It has to be done in a secure environment, on a laptop that has never been online and that will never be online, with WiFi/BT and hard drive stripped and by using tails from a USB stick. Clients can't do this in a secure manner.
2025-10-18 20:35:08 from 1 relay(s) ↑ Parent 1 replies ↓ Reply
That was my question: if we can use the child key to derive addresses from it through signer apps, our initial master key would t he exposed even to these apps. I'm not sure whether we can use BIP85 32 bytes hex to derive addresses.
2025-10-18 20:40:01 from 1 relay(s) ↑ Parent Reply
It would be great if your NSEc derived a Border Wallet. From the Border Wallet, pick one 11-word seed and one for the checksum. That child PK would make a public paynyms/silentpay address. Rotate your keys as you wish.
2025-10-18 20:53:32 from 1 relay(s) ↑ Parent 1 replies ↓ Reply
I would pay a bounty for this feature. Cake Wallet already had a full version of this feature, even though it was in the beta phase. Nostr needs this feature by default. On-chain needs to be used more and have more social use cases.
2025-10-18 21:48:16 from 1 relay(s) ↑ Parent 2 replies ↓ Reply
I connected it to my NWC with local alby hub. the shows dont show. What am I missing. Also tried to import WIF into some wallets but they none seem to have support for taproot. should I go for Core? what am i missing.. I sent some funds and want to recover.. Its a fun mission..
2025-10-19 16:22:33 from 1 relay(s) ↑ Parent Reply
People have many Bitcoin wallets with different purposes. I am not totally sure what you are saying here, that someone without Nostr can send Bitcoin to it.... i am not sure what problem you are solving? (i mean this as a postivite question). To receive bitcoin, I have to give a Bitcoin or lightning address to the sender, so now i have to give them an npub?
2025-10-19 17:54:29 from 1 relay(s) ↑ Parent Reply
>It's not possible to sign an arbitrary message with any sort of signature scheme by Trezor. > >It would be really stupid to allow this: if the message is arbitrary, you can stuff in, say, a valid Bitcoin transaction. Then it's a matter of crafting a clever malware, telling the user: "Security check: please confirm the following characters on your Trezor screen to validate your wallet", and stealing their money. > >The SignMessage APIs look like they accept an arbitrary message, but they don't sign it: the data that is actually signed is "Bitcoin Signed Message:\n(11 bytes)hello world" or something along these lines. > >Even if that is good enough for you, this feature currently does not support Schnorr signatures :( because there hasn't yet emerged a standard for taproot message signing. Source: https://www.reddit.com/r/TREZOR/comments/vrftwn/comment/iexubo7/
2025-10-20 03:52:35 from 1 relay(s) ↑ Parent 2 replies ↓ Reply
that basically says the user is a security vulnerability or we have a too complicated system where users need to sign events that they don't understand? :) (at the same time users complain they get asked too much) and any signing prompt is imo better than handing over the private key. generally the user needs a bit of trust in the webapp. otherwise signing something is never a good idea imo. I think there is a signPsbt function.
2025-10-20 10:33:08 from 1 relay(s) ↑ Parent Reply
do you think there is a difference between a hardware wallet and a web wallet associated to a nostr key? for me it’s kinda confusing to apply something from hardware wallet to a web wallet that works with a nostr key and also prompts users for the actual private key
2025-10-20 14:24:31 from 1 relay(s) ↑ Parent Reply
I want a solution that is ready to use straight away on nostr and with it, all npubs can receive a private on-chain transaction on their profiles. Only the sender knows your public address.
2025-10-20 17:54:35 from 1 relay(s) ↑ Parent Reply
So, lightning payments are public normally. That means we can see who zapped who. We can't, however, see what the receiver of that zap then did with it later. With this, we'd be able to. Not trying to shit on it or anything, just understand the limitations. Seems like it'd be best to at LEAST submarine swap, lightning swap, or coinjoin before spending.
2025-10-20 22:23:50 from 1 relay(s) ↑ Parent Reply