Oddbean new post about | logout
 Why do I need to set a password for my @nostr.build account? 
https://image.nostr.build/46564a610b603537aef7066a99fb55745c52f473cc5ba46610f78db733394100.jpg 
 Am I misunderstanding something?  
 I never want to create another account or set another password again. This is #nostr  
 One the one hand, yes. I love the convenience of using my nostr keypair everywhere. On the other hand... don't love the idea of all of my accounts being perma-pwned because I made a mistake and exposed my privkey. 
 #reckless 
 They can't lock you out of your private key is exposed though  
 I feel the same way. 
I love the idea of one login but like can I put protection on before adding it to a website? Especially on the phone 
 For real. I get so annoyed now when I have to  
 Canceled Password Culture with #Nostr 
 to unlock your passwordless nostr experience

"enter password" 
 You can still use your key pair and ‘nsec bunker’ to login, but like Fishcake said, it’s a security feature.
Also, a lot of people don’t want to use a keypair tool or login with their private keys. We have options! 
 I can't get past the "set a password" screen when trying to sign up for premium. Maybe I'm stupid 🤷 
 just breathe in




and blame the design 
 #metoo
 
 i also know your npub. if you dont password protect it, i guess i could access it 
 That's not how this works. That's not how any of this works or should work. Gaaaah  
 yeah I'm not an expert but npub logins seems wacky 
 @The Fishcake🐶🐾 
 Because that’s how we have had accounts in the beginning, where nostr authentication was added later. This also serves as a second layer of protection if you lose your nsec or if it gets compromised. 🐶🐾🫡 
 Alright, so that's technical debt is what you're saying. 

Please consider changing this. I don't want to deal with my password manager in the nostr world. Password managers are a symptom of a broken system, and imho #nostr fixes this.  
 Use the other login option. Don't need a password. 
 That's not the issue. I want to upgrade to a premium account and I'm forced to set a password.  
 Ah, I see. Only on the new account creation. 
 Isn’t the catch that you have to trust every app that takes your nsec? 
 But yeah the npub is public anyway  
 Outdated tech
nostr:nevent1qqsg4y2gxy9vj0qz3l08lvgxga3jg2s57qycqy3g4snzwavr3q0h6yqpr3mhxue69uhkummnw3ezucnfw33k76twv4ezuum0vd5kzmqzyphydppzm7m554ecwq4gsgaek2qk32atse2l4t9ks57dpms4mmhfxqcyqqqqqqgt3l5l6 
 I guess they are full and want to limit the access ! 
 You don't have to. You can login with npub+DM. 
 nostr:nevent1qqs8gvwtpgctsntylhj3hvm5usrth4rla2ty0rcyuxxqdqxez6jwuaqpz3mhxue69uhkummnw3ezummcw3ezuer9wcpzqmjxss3dld622uu8q25gywum9qtg4w4cv4064jmg20xsac2aam5nqvzqqqqqqy3j6fu0 
 Personally, I prefer not to paste my nsec everywhere, but I also hate the need for an additional password 😅 

@Derek Ross Could you maybe add a lightning login feature? 🙏 
 i don't have a password for my nostr.build, i use NIP-07 and alby nostr keychain and i pay in sats 
 fight me 
https://image.nostr.build/08ecc6a54a8bbe2a92b0a5edba42d4434027ed3d5119ded186ff4f6895d9c6be.jpg 
 It’s not passwords, it’s “users”. You are not an owner, that’s why you have to register 
 Ya, na, PMs are a symptom of many systems. It is what it be. 
 We have key managers now. FIDO, passkeys, WenAuthn etc.

That's my world. 
 we have had EC PKI for over a decade now, it is time to move on, i agree

a keychain like this literally only has to be a few keys which you segregate for purposes or alts

there is already public registries of these keys but honestly the state of PKI is still pretty bad, and you would have to be silly to have me believe that pgp is fine, if it was then explain why it's becoming very common to use SSH for git repo auth?

i wouldn't say it's a symptom of a broken system so much as a failure of tech companies to care about security, which should be considered to be suspicious

that's worse than broken, that's corrupt 
 🏳️🏳️🏳️ .. you won, I surrender. 
 Es verdad - my bitwarden has 239 entries... 
 Ya, na, PMs are a symptom of many systems. It is what it be. 
 I actually have my account on a different npub and I don't always use my own computer, so I do use the password login. 
 can mom and dad stop fighting already? 
 we have had EC PKI for over a decade now, it is time to move on, i agree

a keychain like this literally only has to be a few keys which you segregate for purposes or alts

there is already public registries of these keys but honestly the state of PKI is still pretty bad, and you would have to be silly to have me believe that pgp is fine, if it was then explain why it's becoming very common to use SSH for git repo auth?

i wouldn't say it's a symptom of a broken system so much as a failure of tech companies to care about security, which should be considered to be suspicious

that's worse than broken, that's corrupt 
 is the signup flow include this? i didn't realise it did, i thought it was just based on nostr cryptography? 
 oh i see, looking at my keepassxc yes indeed i stored a password for it

it seems very redundant 
 yeah, i saw the password has a prefix that looks generated 
 🏳️🏳️🏳️ .. you won, I surrender. 
 No, you said "options" and @Gigi as if understood setting a password is optional, but what you meant was logging in with a pw is optional - setting a password is not.