docs: replace blanket 'keys never leave the machine' claim with per-mode truth
External NIP-46 signer mode is a stronger posture, not a caveat: the key never arrives on this machine, so a compromised desktop cannot extract it. The old claim only holds for embedded/bunker modes and undersold the external-signer option. UI already ranked modes correctly; no code change.
This commit is contained in:
parent
e6ddc53261
commit
d4d87b85b6
3 changed files with 13 additions and 7 deletions
12
README.md
12
README.md
|
|
@ -1,7 +1,8 @@
|
|||
# Nostr Feed Manager
|
||||
|
||||
> A friendly Linux desktop app for managing Nostr profiles, publishing notes, and acting as a
|
||||
> **NIP-46 remote signer** — all while your private keys never leave your machine.
|
||||
> **NIP-46 remote signer** — your private keys stay under your control: encrypted in a local
|
||||
> vault, or, when you connect an external signer, held only on that device.
|
||||
|
||||
[]()
|
||||
[](LICENSE)
|
||||
|
|
@ -258,8 +259,13 @@ Your keys are the crown jewels in any Nostr app, and nothing here compromises th
|
|||
(`set-password`, or Settings → Storage). Once set, every secret key is encrypted with
|
||||
**AES-256-GCM** under a key derived from your password with **Argon2id**. Labels and public keys
|
||||
remain readable so you can browse profiles while the vault is locked.
|
||||
- **In-memory key only.** You unlock once per session; the derived key lives only in memory and is
|
||||
never written to disk.
|
||||
- **In-memory key only.** You unlock once per session; the derived key lives only in memory and
|
||||
is never written to disk.
|
||||
- **External signer mode can be *more* secure.** The Signer screen can also use a NIP-46 signer
|
||||
located elsewhere (Amber on your phone, a hardware-backed signer, a bunker you host). In that
|
||||
mode no secret key exists on this desktop at all — signing happens on the signer device, so a
|
||||
compromise of this machine cannot expose the key. "Keys never leave the machine" describes
|
||||
embedded and bunker modes; in external mode the key never *arrives* on this machine.
|
||||
- **Approve-before-any-signing.** The NIP-46 remote signer will not sign, encrypt, or decrypt
|
||||
until you explicitly approve each request.
|
||||
- **Least-privileged storage.** Files are written with directories `0700` and files `0600`.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue