I believe you can have the airdrop tool [0] output the raw bytes that you need to sign with your private key. Still not fool proof but makes it more transparent what you're actually doing with the key.
The next step on the Namebase website is that they ask you for your passport and utility bills, and since they issued the address of your wallet, they perfectly know who received the reward. (as a note I really don't see the point of the crypto-privacy protocol, if it's supposed to hide who received rewards if you need to give your passport to transfer the coins out or exchange against other currency).
Several hours, flipping the code in many ways, such option doesn't seem to exist (and for sure isn't documented)
while (br.left()) {
const ct = br.readBytes(br.readU16(), true);
qqq++;
try {
out.push(key.decrypt(ct, priv));
} catch (e) {
continue;
}
}
What you do is that you bruteforce 1500 items with the private key of the user to find the nonce.
So obviously, the --bare mode cannot work the way you describe.