I am aware of efforts to improve on this though, for example https://snort.social/e/note1crl44xk24yc2ym5xlyyfjdeumxueyguz... - essentially the equivalent of a custodial wallet, if I'm understanding correctly.
I am aware of efforts to improve on this though, for example https://snort.social/e/note1crl44xk24yc2ym5xlyyfjdeumxueyguz... - essentially the equivalent of a custodial wallet, if I'm understanding correctly.
Nostr hasn’t grown up to that yet, and pointing out that pasting private keys is a bad idea is fair game.
But implying that public private key cryptography can’t be used to log into web apps is just silly given that value worth billions is being moved around daily using such web apps.
Both of these do a challenge-response style authentication with a particular website, and wouldn't really work as part of a decentralized system.
You could use the same signing key ordinarily used to sign authentication challenges to sign nostr notes, but then you're back to square 1 really.
Edit: slightly better passkey info here https://developers.yubico.com/Passkeys/How_passkeys_work.htm...
That greater compatibility came with some UX trade-offs though. Now that passkeys exist and are widely supported by web browsers there's really no need for SQRL anymore; passkeys are a far more polished version of the same concept.
Why not offer both, the easy one for normal users and an option to use the more secure option.
Couldn't there be a few-step UI similar to "Sign in with Google/Facebook/etc"?
The only thing that bugs me about is that is actually all your identities are still tied to same master passphrase, so if that gets compromised all of your identities get revealed.
A short guide, assuming a mobile device:
1. Install MetaMask, next, next, finish to create a wallet.
2. Open app.uniswap.org on your favorite browser. See if you can figure out how to ‘connect’.
You can of course use the MetaMask built-in browser, but that’d be cheating.
If you already have MetaMask/Phantom extensions installed it’s easier than email verification.
Im working on https://github.com/VnUgE/NVault as an option for more paranoid users that want a self hosted networked approach. But there are others listed here https://github.com/nostr-protocol/nips/blob/master/07.md
Finally, I wholly dislike the practice of offering an option of entering an nsec. Use a signing extension!