Join Nostr
2026-02-24 19:10:55 UTC
in reply to

leon on Nostr: hey David. every existing proposal has the same flaw: if an attacker has your nsec, ...

hey David. every existing proposal has the same flaw: if an attacker has your nsec, they can publish the same migration event you can. you can't prove who did it.

i am proposing below a scheme that fixes this using a hash commitment published on day one, a sha256 of a passphrase that lives only in your head (a password or something).

attacker can't rotate without knowing it. if they try, the fraudulent rotation is cryptographically distinguishable from a legitimate one.

key theft becomes detectable, not just disruptive.

draft NIP: https://github.com/nostr-protocol/nips/issues/2237

check it out, and let me know your thoughts!

#nostrbuild #keyrotation #cryptography