Oddbean new post about | logout
 Which security and privacy issues are you talking about? 
 If you loose your Nostr key you loose your whole identity. DMs on Nostr leaks metadata etc. You maybe expose your IP address to relays etc.  
 > Losing keys.. 

So, you prefer to give your keys to a company that can do anything as if they were you... That is not safer or more private. The company can and is tracking you everywhere. 

> Metadata

DMs on Nostr don't leak metadata anymore. Just use the new one. It has been live for over a year. 

> IP address

Proton doesn't protect you against IP leakage. Every time you connect to any server, your IP leaks, including Proton's.
 
 I don't give any keys to any comoany, first of all. About the rest, this depends on many things 😉 
 You can't create a wallet without creating a proton account, which is controlled by them. You have to give them ability to control your id. 
 nostr:nevent1qqs08p8h2xkhfp2ts04q4sm32nq4657enhesy6l0l4e6hdu3h4ty82gpz4mhxue69uhhyetvv9ujumn0wd68ytnzvuhsygztqvqpecc5m3pv75h8sg60ms0d8e4ge92ka70f5wmauequeg76wypsgqqqqqqs3tr2kv 
 See, you agree. Nostr is way better. 
 I don't agree that Nostr is better. I'm a big fan of splitting your social media activity from other stuff. Don't use the same key for thousand things.  
 You don't need to use the same key. Just the same protocol that you control the key you want to use. 
 For that Nostr needs a better key management like Master / Child keys.  
 Sure, that will help. But managing multiple keys is not hard. A regular password manager solves most of the way. There is no need to link keys together with a Master / Child crypto scheme. 
 But currently if Iwant to take my I D across different nostr clients. I have to use same nsec don't I?  
 Only if you want your follows to see what your are doing with the other ID. For instance, I have another ID for DMs and another ID for my health data. 

If you are on Android, you can use Amber to sign for any other app. If you are on the Web, you can use browser extensions to sign.  
 Master/child, or "delegates" as some call them, or "certificates" as they're called in the real world, are needed for hot/cold storage and for repudiation. 
 nostr:nprofile1qqsyvrp9u6p0mfur9dfdru3d853tx9mdjuhkphxuxgfwmryja7zsvhqpzamhxue69uhhv6t5daezumn0wd68yvfwvdhk6tcpz9mhxue69uhkummnw3ezuamfdejj7qgwwaehxw309ahx7uewd3hkctcscpyug why don't you stay in your lane and write some myLabel.setText code or something. 
 Why don't you stay in your lane and go play tic tac toe or something. 
 nostr:nevent1qqsw0t08tnr6vcsvcx6ps52ejr0gpdhc868t5zhjty3wjn0794vfwxgpyfmhxue69uhkv6tvw3jhytnwdaehgu3wwa5kueflvakx7cnpds7kzmrvqgsyawyrzrttfmv4cmtx5w2m85702kdct7hv3amfrkhagpdf9cz46mgrqsqqqqqpkzkqm8 
 Use orbit and hire your ass in tor 
 I use InviziblePro 😉 
 I use #grapheneOS 
what does Quebes offer that  GOS doesn't? Thanks  
 QubesOS is for desktops and I think it's the best "OS" when it comes to privacy and security.
 
 "Best" daily driver anyway. Tails is awesome too, but for a very different usecase. 
 Yes, Tails is a great tool and I use it too. But as you said it has a different usecase. If it would be easy to spin up a RAM based QubesOS VM maybe I would drop Tails.