What is Nostr?
JeffG
npub1zuu…c2uc
2024-02-07 17:49:58
in reply to nevent1q…w2eh

JeffG on Nostr: Yup, it's true. Bunker has to be able to decrypt the key in order to sign with it. ...

Yup, it's true. Bunker has to be able to decrypt the key in order to sign with it. The user provides a password that is used to encrypt at rest but when the key is needed for signing the Bunker has to decrypt it (with the password you provide). The key is used and then re-encrypted.

This is why it's important that the code for something like Nsecbunker is open and (ideally) it would be verifiable that a bunker service is running the exact same code so you know they haven't done anything fishy.
Author Public Key
npub1zuuajd7u3sx8xu92yav9jwxpr839cs0kc3q6t56vd5u9q033xmhsk6c2uc