It is literally internet magic that I can use a bunch of different #nostr services that all just sign in with the @getAlby extension. I dont have ANY passwords or account names or emails or privacy issues with even a single one of these services. They all just sign in with my #nostr account and it takes ONE click. On top of it all I'm not putting myself or my passwords or personal info at even the slightest risk by using all of these external services. I literally am annoyed that the rest of the internet doesn't work like this.
The tradeoff though is that now the browser extension has access to your entire browser storage, and the nostr key which is irrevocable is technically theirs. Something like nsecBunker but more protocolized should remedy this.
how is it technically theirs? you store it client side. it doesn't go to their servers. and if you don't trust them, then download the source, compile it yourself, and run the extension yourself. https://github.com/getAlby/lightning-browser-extension
Sure if you compile your own extension sure it takes the "them" out of the equation. Otherwise it's still custodial nostr. Iirc they do provide backup via email auth? Opting in to that is fine but now the scope is your whole browser. And then your still left needing a whole different method on your phone. Feeding a nip07 scriptlet with nsecBunker signatures could be a trivial to self host answer.. putting it on the hit list.
Right there with ya, man.
The guy who made the worldwideweb, http, html etc. literally co-wrote a standard to do this for the whole web, in 2007. I remember showing it to @slush in 2013. Everyone ingored it though. Even after nostr it took about a long time working with @bumi and alby to get it into nostr. It was a long road to get this far. There is also a ton of stuff in nostr today that people that have not noticed but is more powerful than anything that came before ...
Internet magic with magic internet money baked in. And it will get better still. nostr:nevent1qqs0py5tvj2j7f4qffjmu0pt0h4nwglt7gwquyuv6lakw2smj2tsjtgpz4mhxue69uhk2er9dchxummnw3ezumrpdejqyg9euaj5dwsxg4hdxqweu54uf8ay3ec2d0ezs2l85xh899rkzgprmspsgqqqqqqsvv0tv3
Except for the fact that Alby has you private key
Did alby pass any independent audit? Is there any supply chain attack considered? Do you have plan if your nostr pk gets compromised? Are you willing take 100% responsibility to not lose your pk accidentally? Do you expect your mom to take the same level of responsibility? Its good to highlight pros but you must pay more attention to cons