Derek Ross on Nostr: Good morning and pura vida, Nostr! Your nsec is your identity, your followers, notes, ...
Good morning and pura vida, Nostr!
Your nsec is your identity, your followers, notes, zaps, all signed by one key. So keep it out of harm's way:
📱 Remote signer on your phone (Amber, Clave, etc.): apps request, you approve with a fingerprint or PIN, your key never leaves the app.
💻 Signing extension on desktop (Ditto, Alby, etc.): sites request, the extension signs, your key never touches a web page.
🔒 Never paste your nsec anywhere. Not even apps that I promote or work on. Always assume that these could leak your keys at some point in the future.
Your identity should require your thumb, face, a PIN, some manual intervention, etc. Keeping your keys safe is paramount.
Stay vigilant!
Published at
2026-09-03 13:18:36 UTCEvent JSON
{
"id": "fe3e6d0f462b3aca8c03d7d48f8153eb03fa37c306e200c2ef1674846aca26a3",
"pubkey": "3f770d65d3a764a9c5cb503ae123e62ec7598ad035d836e2a810f3877a745b24",
"created_at": 1788441516,
"kind": 1,
"tags": [
[
"client",
"Ditto",
"31990:781a1527055f74c1f70230f10384609b34548f8ab6a0a6caa74025827f9fdae5:ditto"
]
],
"content": "Good morning and pura vida, Nostr! \n\nYour nsec is your identity, your followers, notes, zaps, all signed by one key. So keep it out of harm's way:\n\n📱 Remote signer on your phone (Amber, Clave, etc.): apps request, you approve with a fingerprint or PIN, your key never leaves the app.\n\n💻 Signing extension on desktop (Ditto, Alby, etc.): sites request, the extension signs, your key never touches a web page.\n\n🔒 Never paste your nsec anywhere. Not even apps that I promote or work on. Always assume that these could leak your keys at some point in the future.\n\nYour identity should require your thumb, face, a PIN, some manual intervention, etc. Keeping your keys safe is paramount. \n\nStay vigilant!",
"sig": "783ead4fe0be81519c5896b8652fc65f2e8d3b5a8df15cd554c7f03c759b4da832b69db833f18330a5fc783b22ea61652db479238aef980b5bde9f31cf2e9ec8"
}