Oddbean new post about | logout
 the fact that using nostr requires private key management seems like a great way to get precoiners comfortable with personal responsibility without money on the line 
 That’s a great point. 
 True... there is a bit of risk in people treating btc keys like nostr keys though... despite the gross difference in risk. 
 This will be the natural foot in the door for self-custody.  From this seed will grow into the sun.   
 I agree... it's a net positive, but I worry some will learn key management with low stakes and get burned when the stakes are higher. We will be there to help though :). 
 exactly 
 💯🤙 
 I still think we can onboard with passwords and Bitwarden 

I don’t want it to deter new people, but give them a chance to shift from passwords to private keys 
 💯 
 Yes, I was thinking the same. Individuals as well as pre coiner organizations.
As Nostr becomes popular there will be organizations who would want to use Nostr, and will end up setting up private key management processes. 
 I don't see the "forgot password" link when logging in. What gives?  
 True but still sketchy to put your private key in a random website/client. The stakes are very low in an emerging social network (where followers, history etc aren’t super valuable) so it’s fine for now but needs to be solved for at some point I think 
 I think that's a good point. Safe and private management of private keys is no small order.
 
 Yes, and then moving on to hardware devices because your data, communications and social media identity are valuable despite not being money. 

Eventually people will want hardware signing devices for private key security. 
 It is somewhat worrysome setting up private keys in Nostr ecosystem right now, just because the keys must be so exposed to interact. Wonder if there will be a private key transfer mechanism in the future so that we can transfer profile to secure private key.
 
 This is it guys , Nostr!!!!! 
 🍆 to 🧡 
 Dammit meant to send this 💜 
 lolz 
 Perfect way to indoctrinate. 

Looking forward to clients implementing NIP-06 for BIP-39 seed-based key management.  
 What are some suggested key management solutions?  
I would like to take more steps in improving my opsec. 
 Yes and no. The web clients (for now) require you enter your private key into a website 🤢 
 It's a Trojan Horse 
 Great point 
 In some ways it's even worse than bitcoin key management. At least with bitcoin it's easy enough to move your coins over to a new key if security with one is uncertain. Nostr needs key invalidation/rotation. 
 We are not too far from a rogue app stealing private keys.  And the media will FUD it to max effect. Devs and leaders should try to get ahead of this almost guaranteed scenario.