<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-01-12T09:36:57Z</updated>
  <generator>https://nostr.ae</generator>

  <title>Nostr notes by yas</title>
  <author>
    <name>yas</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://nostr.ae/npub1x8c26vdzu4v8my7ujljph2f73syql0kyd08ae0h4tk3gr22fdufqc38fl0.rss" />
  <link href="https://nostr.ae/npub1x8c26vdzu4v8my7ujljph2f73syql0kyd08ae0h4tk3gr22fdufqc38fl0" />
  <id>https://nostr.ae/npub1x8c26vdzu4v8my7ujljph2f73syql0kyd08ae0h4tk3gr22fdufqc38fl0</id>
  <icon></icon>
  <logo></logo>




  <entry>
    <id>https://nostr.ae/nevent1qqsdg6x3dya3g83zxegqheemuvdq6qdwee8p9a9umrsjrnp6d95lhfgzyqclptf35tj4slvnmjt7gxaf86xqsra7c34ulh9774w69qdff9h3yrqeqfn</id>
    
      <title type="html">Re 5. The passkey is used explicitly for the wallet. Re 6. A ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsdg6x3dya3g83zxegqheemuvdq6qdwee8p9a9umrsjrnp6d95lhfgzyqclptf35tj4slvnmjt7gxaf86xqsra7c34ulh9774w69qdff9h3yrqeqfn" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsd4lf4zepc3gvs2zleyz7vwe0f782rj0kwen8uw2vymr23nf8uedsprdmhxue69uhhyetvv9ujuumwdae8gtnnda3kjctv8g6nw27eyyx&#39;&gt;nevent1q…eyyx&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Re 5. The passkey is used explicitly for the wallet.&lt;br/&gt;Re 6. A regular user doesn&amp;#39;t store his passkeys in his desktop, and the passkey stays in his phone or physical key and only the prf result is sent to the desktop. &lt;br/&gt;&lt;br/&gt;
    </content>
    <updated>2026-01-13T14:29:18Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqsgwcd8nl389v8gttvhvz5xzec8ntve7e3c889w3v5l6elahvyy7yszyqclptf35tj4slvnmjt7gxaf86xqsra7c34ulh9774w69qdff9h3ygqhpnc</id>
    
      <title type="html">1. The client can regularly check the relays and republish the ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqsgwcd8nl389v8gttvhvz5xzec8ntve7e3c889w3v5l6elahvyy7yszyqclptf35tj4slvnmjt7gxaf86xqsra7c34ulh9774w69qdff9h3ygqhpnc" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs2ckgpdzfvcxgjpyrj40znu449c5tllaaqrd68dkqcfs39y9ze7gqpzemhxue69uhhyetvv9ujuurjd9kkzmpwdejhg0x5pn7&#39;&gt;nevent1q…5pn7&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;1. The client can regularly check the relays and republish the list of salts if they are deleted.&lt;br/&gt;2. Every vendor can setup their own relay.&lt;br/&gt;3. The list of salts is backup-ed automatically by ios/android because its in the app data and is not &amp;#34;secret&amp;#34;.&lt;br/&gt;4. The same list can be exported by the client to a simple text file if the user wants a wallet independent backup and doesn&amp;#39;t want to run any app using this protocol for a long time.&lt;br/&gt;5. Passkey rotation is generally not needed because the secret part of the passkey is not supposed to leave the TEE except when migrating from one vendor to another (using a secure protocol like CXP). In the exceptional case of a passkey compromise, the user can always move its funds to another wallet using a new passkey.&lt;br/&gt;6. The UX cost of using iCloud/GDrive is very high (login, vendor auth)
    </content>
    <updated>2026-01-12T13:15:17Z</updated>
  </entry>

  <entry>
    <id>https://nostr.ae/nevent1qqswdc03lexzfcp5nr3e3sm6p9u6r8wmrrsndcm792v6ufhs3ujsefczyqclptf35tj4slvnmjt7gxaf86xqsra7c34ulh9774w69qdff9h3yzxt6tl</id>
    
      <title type="html">The primary salt is an hard coded string defined in the protocol. ...</title>
    
    <link rel="alternate" href="https://nostr.ae/nevent1qqswdc03lexzfcp5nr3e3sm6p9u6r8wmrrsndcm792v6ufhs3ujsefczyqclptf35tj4slvnmjt7gxaf86xqsra7c34ulh9774w69qdff9h3yzxt6tl" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsx5g9f6whsl3da2s600sryqej6vzsth6k8skxt4mmz7fd0652alrspzemhxue69uhhyetvv9ujuurjd9kkzmpwdejhgqmacg2&#39;&gt;nevent1q…acg2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;The primary salt is an hard coded string defined in the protocol. Using it the list of the salts used by the same passkey can be obtained from the relays.&lt;br/&gt;If by &amp;#34;the user trusts his nostr relays to store the salt&amp;#34;, you mean to trust the relays to not delete them, trusting iCloud/GDrive is not better.&lt;br/&gt;Also, Breez intent is to mitigate the trust by handling a relay dedicated to store the salts.
    </content>
    <updated>2026-01-12T09:45:44Z</updated>
  </entry>

</feed>