docs: replace blanket 'keys never leave the machine' claim with per-mode truth

External NIP-46 signer mode is a stronger posture, not a caveat: the key
never arrives on this machine, so a compromised desktop cannot extract it.
The old claim only holds for embedded/bunker modes and undersold the
external-signer option. UI already ranked modes correctly; no code change.
This commit is contained in:
Avi 2026-09-22 17:46:17 -05:00
commit d4d87b85b6
3 changed files with 13 additions and 7 deletions

View file

@ -1,7 +1,8 @@
# Nostr Feed Manager
> A friendly Linux desktop app for managing Nostr profiles, publishing notes, and acting as a
> **NIP-46 remote signer** — all while your private keys never leave your machine.
> **NIP-46 remote signer** — your private keys stay under your control: encrypted in a local
> vault, or, when you connect an external signer, held only on that device.
[![Version](https://img.shields.io/badge/version-0.1.0-blue)]()
[![License: MIT](https://img.shields.io/badge/license-MIT-yellow.svg)](LICENSE)
@ -258,8 +259,13 @@ Your keys are the crown jewels in any Nostr app, and nothing here compromises th
(`set-password`, or Settings → Storage). Once set, every secret key is encrypted with
**AES-256-GCM** under a key derived from your password with **Argon2id**. Labels and public keys
remain readable so you can browse profiles while the vault is locked.
- **In-memory key only.** You unlock once per session; the derived key lives only in memory and is
never written to disk.
- **In-memory key only.** You unlock once per session; the derived key lives only in memory and
is never written to disk.
- **External signer mode can be *more* secure.** The Signer screen can also use a NIP-46 signer
located elsewhere (Amber on your phone, a hardware-backed signer, a bunker you host). In that
mode no secret key exists on this desktop at all — signing happens on the signer device, so a
compromise of this machine cannot expose the key. "Keys never leave the machine" describes
embedded and bunker modes; in external mode the key never *arrives* on this machine.
- **Approve-before-any-signing.** The NIP-46 remote signer will not sign, encrypt, or decrypt
until you explicitly approve each request.
- **Least-privileged storage.** Files are written with directories `0700` and files `0600`.