What is Nostr?
boilerhodl /
npub14y9…8xet
2023-10-26 12:11:26
in reply to nevent1q…5c87

boilerhodl on Nostr: If an attacker had your TAPSIGNER, they'd still need your username/password to ...

If an attacker had your TAPSIGNER, they'd still need your username/password to authenticate and vice versa. We don't secure funds with these Tapsigners. They are only for 2-factor authentication, so the Best Practice violation seems like a reasonable trade-off for this use case.
Author Public Key
npub14y9984l32yr3jna9gsh5lz9l6l2yp3uxx8nxrav6u3jcr8duhhhqzg8xet