π₯ RDWE Nostr Signer: The Only NIP-07 Signer That Actually Protects Your Keys π₯
Tired of Nostr signers that store your nsec in plain text? Sick of extensions that leak your identity with one browser exploit? Meet the RDWE Nostr Signer β the first (and only) signer that encrypts your key with AES-256-GCM before it ever touches storage.
Why This Signer Obliterates the Competition
β
Zero Plaintext Exposure β Your nsec is PBKDF2-SHA256 hashed (310k iterations) + AES-256-GCM encrypted before storage. No malware, no extension leak, no problem.
β
Session-Locked β Auto-locks after 15 min idle. No nsec in memory when youβre not using it.
β
Smart Request Queue β No more 5 popups for 5 requests. One window, all approvals.
β
Zero Dependencies β Pure JS, no node_modules, no supply chain attacks.
β
Open Source & Auditable β GitHub β Every line is yours to inspect.
β
Works Everywhere β Primal, Snort, Iris, Coracle, Nostrgram, Zap.stream, and more.
π¨ The Problem With Other Signers
Every other NIP-07 signer stores your nsec as plain text in chrome.storage.local. One exploit = your identity is gone.
RDWE never stores your nsec in plain text β not on disk, not in memory, never.
π‘ How It Works (Architecture)
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β WEB PAGE
β window.nostr.signEvent(event) βββ inject.js (MAIN)
β β postMessage
βββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββ
β
βββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββ
β content_script.js (ISOLATED)
β Bridges page β background via chrome.runtime
βββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββ
β chrome.runtime.sendMessage
βββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββ
β background.js (SERVICE WORKER)
β β Validates permissions
β β Opens approval popup if needed
β β Signs / encrypts / decrypts
β β Returns result (never the private key)
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Your private key is stored in chrome.storage.local β accessible only to this extension, never to web pages.
Your nsec β PBKDF2-SHA256 (310k iterations) β AES-256-GCM encrypted blob β stored in chrome.storage.local.
Session locked by default β Unlock with your master password (never stored).
Signing requests β Seamless unlock prompt β nsec stays in RAM only during session.
15 min idle? β Auto-wipe from memory.
π» Install in 60 Seconds
Download: GitHub Releases
Unzip β Load in Chrome/Brave (chrome://extensions β "Load unpacked")
Set a master password β Import your nsec (or generate a new one)
Done. Your keys are now military-grade encrypted.
π Compatible With
@primal @snort @iris @coracle @nostrgram @zapstream @habla and any NIP-07 client.
π¨ Warning
No password recovery β If you forget it, you lose access (by design).
No Firefox support (yet) β Chromium only.
No telemetry, no ads, no bullshit β This is 100% for the people.
π¬ Spread the word. The era of leaky signers is over.
#Nostr #NIP07 #Bitcoin #Crypto #Privacy #Security #RDWE #NostrSigner #AES256 #ZeroTrust #OpenSource #Decentralize #Web3 #NostrTools #NostrExtension #NostrSecurity #NostrPrivacy #NostrHacks #NostrDev #NostrTech #NostrInnovation
π GitHub: github.com/RedDragonElite/rdwe_nostr_signer
π€ Creator: @RedDragonElite | Nostr: npub1wr4e24zn6zzjqx8kvnelfvktf0pu6l2gx4gvw06zead2eqyn23sq9tsd94
π₯ Retweet, like, zap β letβs make Nostr secure again!
