Oddbean new post about | logout
 We're talking about different things.  

If you share a password/nsec, multiple services can be comprimised at once. 

If you type a password/nsec into a shady app (proton, a proton companion or clone, or anything else), it'll be compromised.  

Both points are true.  People shouldn't do either.  

People are already better (but still bad) at not reusing passwords.  Painting an equivalence between passwords and nsecs helps folks grok the problems with nsec reuse.

Painting a distimction between them creates some very difficult differences in our expectations.

"Identity" on the other hand is distinct, and we do need a way for multiple nsecs to sign for one identity, the same way we have ways to allow multiple passwords to authenticate the same human.