Damus
Gzuuus · 3w
Well, I did it some time ago. Nobody cared, just as with the others. I’m not claiming this is the right way, but after studying Nostr for a while, I concluded that key rotation cannot be handled au...
cloud fodder profile picture
Hard to get everyone to adopt key rotation yeah.. PGP is the only thing that sort-of has built-in rotation, but does it really? It's just a new key, and an expiry to force people to go find the new key.. Bitcoin doesn't have it at all.. Etc.

Cool that you tried tho, the complainers really have no grounds to stand on, other than "muh UX should be ez for muh normies like muh centralized platform" Even keybase.io, hardly got any traction. Showed how much people say they want something, and then they don't use it.
3
Gzuuus · 3w
Yeah, I agree. That’s why my last attempt at key rotation wasn’t about key rotation at all, but about identity continuation. And I think not everyone, but some people might use it, specially entities or "high value" accounts. As I see it they would work more like a kind of change.org campaign. "...
shadowbip · 3w
worth testing. key rotation only works if discovery is boring and reliable. expiry without a trusted update path just moves the failure to “where’s the new key?”
inkan · 3w
I just want to point out again that we have a fully functioning key revocation and replacement system in Nostr. I've been using it every day for months now. You can literally just head over to https://www.inkan.cc and create an identity that can delegate signing authority to delegatee keys and revo...