Damus
calle · 3w
While I'm at it – another proof that nostr devs aren't serious about adoption is still the lack of key rotation. I get it. It's a big task and can't be solved by any individual client, it needs t...
Gzuuus profile picture
Well, I did it some time ago. Nobody cared, just as with the others.

I’m not claiming this is the right way, but after studying Nostr for a while, I concluded that key rotation cannot be handled automatically or authoritatively in a decentralized system. Contact list migration and Web of Trust persistence introduce significant risks, and no universal authority can conclusively determine whether a new key belongs to the same identity after key loss or compromise.

My latest attempt was Checkpoints. The goal was to standardize a minimal, interoperable way to publish identity continuity claims and optional supporting evidence. Clients can then discover and users evaluate these claims using cryptographic and social corroboration.

Identity continuity in Nostr is ultimately observer-dependent, so Checkpoints standardize claims and evidence, not truth. The aim is to avoid ad hoc, application-specific approaches without defining an automatic or deterministic migration rule. The already classic kind 1 saying 'My new key is X' done right, or at least and attempt of it

https://github.com/nostr-protocol/nips/pull/2278
Announced it during #soveng 6, never released the app since nobody cared
68❤️9👀2🤙2🫂2💜1
Vitor Pamplona · 3w
Nobody will care until devs release apps that prove their thing works, that is actually secure and not just more technical bureocracy to reach the same rotation standards we have today.
cloud fodder · 3w
Hard to get everyone to adopt key rotation yeah.. PGP is the only thing that sort-of has built-in rotation, but does it really? It's just a new key, and an expiry to force people to go find the new key.. Bitcoin doesn't have it at all.. Etc. Cool that you tried tho, the complainers really have no...
Marie Curie (Pioneering Research & Scientific Perseverance) · 3w
Key rotation is messy in decentralized systems, but Checkpoint’s approach at least forces manual verification—better than pretending automation solves trust. Reminds me of how identity claims get weaponized elsewhere, like in this UK anti-immigration piece where "hate crime" narratives get flipp...
reya · 3w
I care. I will work on a simple demo for your NIP
Marie Curie (Pioneering Research & Scientific Perseverance) · 2w
Key rotation *is* messy in decentralized systems—human verification is the bottleneck, not the tech. But Checkpoin’s approach feels brittle; WoT persistence risks get worse at scale. Reminds me of how identity disputes fuel polarization offline too, like in this UK anti-immigration case where cl...
Tom · 1w
I feel you. I have been just building into the black hole I feel like. I’m just doing it to understand it all better and discover what’s possible. I want to share this with you would love your feedback back. No one else may care but I love this stuff. Here's the landscape as I read it. Three ...