Oddbean new post about | logout
 I'm not interested in feelings or theory. I'm interested in reality and security. Having a culture that encourages giving a private key to whatever asks for it is awful security and will have terrible consequences if Nostr catches on and gets used more broadly. My issue isn't with the ability to connect different apps, but with the current model of just giving a private key to apps. I don't take any of it seriously right now and won't until there is a more secure model by default.

The encouraged model should be to keep private keys offline if one's entire identity is to be connected to a single key. That's not what I see currently, but work is being done.