Oddbean new post about | logout
 it will be bad when a client’s domain gets compromised and nsecs leaked via an attack

so people will switch to web based signer apps

then they will be compromised

the only way out is a proper hardware signer, a proper remote signer or a browser extension 
 What's the best way of handling your nsec right now? I use alby extension for zap.stream and Nostrudel and only use Amethyst on mobile. 
 In Amethyst we trust 🙏 
 Public Nostr terminals (like phone booths). Bring your own hardware signer 
 USB hardware device + mobile app/browser plug-in?  User inserts the device when using Nostr apps/sites and removes it when not.