fiatjaf on Nostr: While you're worrying about crafting the best possible way to log in with your Nostr ...
While you're worrying about crafting the best possible way to log in with your Nostr keypair on different apps without leaking your key or comprosing your security or anything, Bluesky is just doing the username/password combo and now
https://whtwnd.com/ has my username and password in raw format, which they use to get a JWT from a Bluesky server which they pass on in future API calls to publish stuff. Not even OAuth.
Published at
2024-05-21 19:45:41Event JSON
{
"id": "ced9fd033ca98471423f5847eaea15ecd10711b82d22f92150145625958c7178",
"pubkey": "3bf0c63fcb93463407af97a5e5ee64fa883d107ef9e558472c4eb9aaaefa459d",
"created_at": 1716320741,
"kind": 1,
"tags": [
[
"client",
"gossip"
]
],
"content": "While you're worrying about crafting the best possible way to log in with your Nostr keypair on different apps without leaking your key or comprosing your security or anything, Bluesky is just doing the username/password combo and now https://whtwnd.com/ has my username and password in raw format, which they use to get a JWT from a Bluesky server which they pass on in future API calls to publish stuff. Not even OAuth.",
"sig": "c55f2c86ee75698ba7aae105eb7a7cd8eb1e63024d458248aaa2a7913eeb2181764d0fdfb60e7f79d4e6cb24b3cb6a1ce6046600b2823aa04ab1f946162ebb93"
}