Oddbean new post about | logout
 you should install Amber asap (and use fdroid or some other non-google app app to get it) 
 First I've heard of it! What makes it special to you? 
 frdoid is an alternative to google play that only provides open source apps

amber is an "isolated signer" which keeps your key and all it does is accept requests to sign things and has a set of permissions controls about what things it will automatically sign, or it pops up and asks you to consent

amber helps you protect your keys from being compromised by a bug in amethyst or other apps... and it also makes it safer to experiment with new apps that do other things, like "pokey", which vitor is always talking about lately, a nostr app that specialises in notifying you of events that you might be interested, like DMs or replies or reactions 
 Yes, I use Obtainium and F-Droid (via the Droid-ify fork) for most of my apps, fantastic software! 🫡

As for Amber, is a bug that exposes my nsec a significant threat? Also, how does it protect your keys? I understand the signing aspect, but couldn't a bug theoretically expose them in Amber as well?