Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> I dont see any reason why an app approach cant support that.

Matrix clients have e2ee encryption like Signal or WhatsApp.

Every single one of my close contacts that I have on my server have ignored or misunderstood the instructions to download and store the recovery key when they first access the servers.

I have customers on my support channel who keep trying different clients (Element, ElementX, Fractal) and every time they fail to validate their sessions.

Then I have customers who got their phone stolen and then come asking me to either delete the data on their phone.

---

There is no magic about "putting it in a app to manage it". If any "app approach" you come up with creates a sandbox between user and device, then the user can not even see their private keys, then they effectively do not own it.

If you are doing "nostr, but with keys sandboxed on the device", then you are just recreating Signal - which is not decentralized - then what's the point?



Sandboxing keys on the device is indeed removing one point of nostr, but to clarify on your point: The difference between Signal and Nostr is that in nostr there are hundreds of independent servers (relays) that your app broadcasts events to, whereas on Signal it's just one centralized server.


There is nothing special about independent relays. ActivityPub also have relays around. Store-and-forward is how IRC works.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: