Oddbean new post about | logout
 Am I misunderstanding something?  
 I never want to create another account or set another password again. This is #nostr  
 One the one hand, yes. I love the convenience of using my nostr keypair everywhere. On the other hand... don't love the idea of all of my accounts being perma-pwned because I made a mistake and exposed my privkey. 
 #reckless 
 They can't lock you out of your private key is exposed though  
 I feel the same way. 
I love the idea of one login but like can I put protection on before adding it to a website? Especially on the phone 
 For real. I get so annoyed now when I have to  
 Canceled Password Culture with #Nostr 
 to unlock your passwordless nostr experience

"enter password" 
 You can still use your key pair and ‘nsec bunker’ to login, but like Fishcake said, it’s a security feature.
Also, a lot of people don’t want to use a keypair tool or login with their private keys. We have options! 
 I can't get past the "set a password" screen when trying to sign up for premium. Maybe I'm stupid 🤷 
 just breathe in




and blame the design 
 #metoo
 
 i also know your npub. if you dont password protect it, i guess i could access it 
 That's not how this works. That's not how any of this works or should work. Gaaaah  
 yeah I'm not an expert but npub logins seems wacky 
 @The Fishcake🐶🐾 
 Because that’s how we have had accounts in the beginning, where nostr authentication was added later. This also serves as a second layer of protection if you lose your nsec or if it gets compromised. 🐶🐾🫡 
 Alright, so that's technical debt is what you're saying. 

Please consider changing this. I don't want to deal with my password manager in the nostr world. Password managers are a symptom of a broken system, and imho #nostr fixes this.  
 Use the other login option. Don't need a password. 
 That's not the issue. I want to upgrade to a premium account and I'm forced to set a password.  
 Ah, I see. Only on the new account creation. 
 Isn’t the catch that you have to trust every app that takes your nsec? 
 But yeah the npub is public anyway  
 nostr:nevent1qqs8gvwtpgctsntylhj3hvm5usrth4rla2ty0rcyuxxqdqxez6jwuaqpz3mhxue69uhkummnw3ezummcw3ezuer9wcpzqmjxss3dld622uu8q25gywum9qtg4w4cv4064jmg20xsac2aam5nqvzqqqqqqy3j6fu0 
 fight me 
https://image.nostr.build/08ecc6a54a8bbe2a92b0a5edba42d4434027ed3d5119ded186ff4f6895d9c6be.jpg 
 It’s not passwords, it’s “users”. You are not an owner, that’s why you have to register 
 Ya, na, PMs are a symptom of many systems. It is what it be. 
 We have key managers now. FIDO, passkeys, WenAuthn etc.

That's my world. 
 we have had EC PKI for over a decade now, it is time to move on, i agree

a keychain like this literally only has to be a few keys which you segregate for purposes or alts

there is already public registries of these keys but honestly the state of PKI is still pretty bad, and you would have to be silly to have me believe that pgp is fine, if it was then explain why it's becoming very common to use SSH for git repo auth?

i wouldn't say it's a symptom of a broken system so much as a failure of tech companies to care about security, which should be considered to be suspicious

that's worse than broken, that's corrupt 
 🏳️🏳️🏳️ .. you won, I surrender. 
 Es verdad - my bitwarden has 239 entries... 
 I actually have my account on a different npub and I don't always use my own computer, so I do use the password login. 
 we have had EC PKI for over a decade now, it is time to move on, i agree

a keychain like this literally only has to be a few keys which you segregate for purposes or alts

there is already public registries of these keys but honestly the state of PKI is still pretty bad, and you would have to be silly to have me believe that pgp is fine, if it was then explain why it's becoming very common to use SSH for git repo auth?

i wouldn't say it's a symptom of a broken system so much as a failure of tech companies to care about security, which should be considered to be suspicious

that's worse than broken, that's corrupt