Our Nsecs are the equivalent of Social Security Numbers we create for ourselves, with similar issues that there's no way to change or update them if they're ever exposed. Likewise, there's no means of safely establishing group identities due to this same issue. We solve this by using our NIP05s as our Unique Identifiers, ideally connected to self-hosted domain names that we control. The added benefit of a matching payment identifier becomes possible by creating LN Addresses, and eventually on-chain Bitcoin Silent Payments, that ALL use the same re-usable, human readable, identifiers.
These issues can be solved by establishing Fedimint Nostr signing of group accounts and by careful Nsec handling and upgraded 'tooling'. This can and will someday enable self-sovereign self-credentialed self-custodied decentralized IDs. Many of us are working on these solutions right now.
