Join Nostr
2026-03-04 18:52:10 UTC

β–³ α›‹α›…αš±α›’α›…αšΎα›α›‹ ᛒᛁᛏᛅ β–½ on Nostr: πŸ”₯ RDWE Nostr Signer: The Only NIP-07 Signer That Actually Protects Your Keys πŸ”₯ ...

πŸ”₯ RDWE Nostr Signer: The Only NIP-07 Signer That Actually Protects Your Keys πŸ”₯

Tired of Nostr signers that store your nsec in plain text? Sick of extensions that leak your identity with one browser exploit? Meet the RDWE Nostr Signer – the first (and only) signer that encrypts your key with AES-256-GCM before it ever touches storage.

Why This Signer Obliterates the Competition
βœ… Zero Plaintext Exposure – Your nsec is PBKDF2-SHA256 hashed (310k iterations) + AES-256-GCM encrypted before storage. No malware, no extension leak, no problem.
βœ… Session-Locked – Auto-locks after 15 min idle. No nsec in memory when you’re not using it.
βœ… Smart Request Queue – No more 5 popups for 5 requests. One window, all approvals.
βœ… Zero Dependencies – Pure JS, no node_modules, no supply chain attacks.
βœ… Open Source & Auditable – GitHub – Every line is yours to inspect.
βœ… Works Everywhere – Primal, Snort, Iris, Coracle, Nostrgram, Zap.stream, and more.

🚨 The Problem With Other Signers

Every other NIP-07 signer stores your nsec as plain text in chrome.storage.local. One exploit = your identity is gone.
RDWE never stores your nsec in plain text – not on disk, not in memory, never.

πŸ›‘ How It Works (Architecture)
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ WEB PAGE
β”‚ window.nostr.signEvent(event) ←── inject.js (MAIN)
β”‚ β”‚ postMessage
└─────────┼─────────────────────────────────────────────
β”‚
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ content_script.js (ISOLATED)
β”‚ Bridges page ↔ background via chrome.runtime
└─────────┼─────────────────────────────────────────────
β”‚ chrome.runtime.sendMessage
β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β–Όβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€
β”‚ background.js (SERVICE WORKER)
β”‚ βœ” Validates permissions
β”‚ βœ” Opens approval popup if needed
β”‚ βœ” Signs / encrypts / decrypts
β”‚ βœ” Returns result (never the private key)
└───────────────────────────────────────────────────────
Your private key is stored in chrome.storage.local β€” accessible only to this extension, never to web pages.

Your nsec β†’ PBKDF2-SHA256 (310k iterations) β†’ AES-256-GCM encrypted blob β†’ stored in chrome.storage.local.

Session locked by default – Unlock with your master password (never stored).

Signing requests β†’ Seamless unlock prompt β†’ nsec stays in RAM only during session.
15 min idle? β†’ Auto-wipe from memory.

πŸ’» Install in 60 Seconds

Download: GitHub Releases

Unzip β†’ Load in Chrome/Brave (chrome://extensions β†’ "Load unpacked")

Set a master password β†’ Import your nsec (or generate a new one)
Done. Your keys are now military-grade encrypted.

πŸ”— Compatible With
@primal @snort @iris @coracle @nostrgram @zapstream @habla and any NIP-07 client.

🚨 Warning

No password recovery – If you forget it, you lose access (by design).
No Firefox support (yet) – Chromium only.
No telemetry, no ads, no bullshit – This is 100% for the people.

πŸ’¬ Spread the word. The era of leaky signers is over.
#Nostr #NIP07 #Bitcoin #Crypto #Privacy #Security #RDWE #NostrSigner #AES256 #ZeroTrust #OpenSource #Decentralize #Web3 #NostrTools #NostrExtension #NostrSecurity #NostrPrivacy #NostrHacks #NostrDev #NostrTech #NostrInnovation

πŸ”— GitHub: github.com/RedDragonElite/rdwe_nostr_signer
πŸ‘€ Creator: @RedDragonElite | Nostr: npub1wr4e24zn6zzjqx8kvnelfvktf0pu6l2gx4gvw06zead2eqyn23sq9tsd94

πŸ’₯ Retweet, like, zap – let’s make Nostr secure again!