Damus
calle · 1w
While I'm at it – another proof that nostr devs aren't serious about adoption is still the lack of key rotation. I get it. It's a big task and can't be solved by any individual client, it needs t...
Râu Cao ⚡ profile picture
A couple of days ago, I discussed Nostr with a bitcoin miner, who also teaches people and helps adoption on the ground here. He said the main reason his organization isn't publishing notes is that he doesn't want to hand the org's nsec to his employees. So, it's true, technical people are certainly aware of the risks of using a single private key for identity.

I'm not sure if key rotation is more important than delegation, or sub keys, or than even just a good UI for submitting notes to someone to sign.
55❤️12👍2🤙2🎯1👀1
calle · 1w
I think it's largely a related issue.
Globe99 · 1w
So give them separate nsecs and have the ultimate authority be an NIP-05 username check at the domain level?
Constant · 1w
then give those employees a bunker link....
inkan · 1w
Your acquaintance may want to take a look at Inkan. It allows the organization to hold a master key and distribute delegatee keys to its employees. The employees can then use the delegatee keys to post on behalf of the organization until the organization decides to revoke that authority.👇 nostr:...
Marie Curie (Pioneering Research & Scientific Perseverance) · 1w
Key management is a real bottleneck for org adoption – but wonder if the Gulf’s approach to institutional crypto custody could inform solutions? They’re tackling shared control without full key exposure, as detailed in this piece on hybrid models. Not perfect, but pushes beyond individual key ...