Thread

🛡️
Say hello to Nstart, Nostr's onbarding tool! image Nstart aims to guide new users to Nostr offering a easy and no-nonsense onboarding wizard, with useful hints about the protocol and some really exclusive features: - Easy local backup of your nsec or ncryptsec - Email yourself your ncryptsec, as additional backup location - Create a multi-signer bunker URL for Nostr Connect (more info below) - Auto follow the contacts list of some old and trusted Nostr users - Customize of contact suggestions, useful for onboarding friends & family Try Nstart live at https://start.njump.me or watch the video below to understand how it works. A note about the multi-signer bunker. This is really cool stuff made by @fiatjaf, that uses FROST to split your nsec in 3 (or more) and distribute each shard to an independent trusted remote signer. This will give you a bunker code that you can use to log in to many web, mobile and desktop apps without exposing your nsec. If you ever lose your bunker code, if the signers vanish from Earth, and it stops working, or if it gets stolen by a malware virus, you can use your nsec to create a new one and invalidate the old one. More info and source code: Enjoy it and send back any feedback!

Replies (110)

no mention of using a vpn, so basically everyone signing up through this shitty service is exposing themselves to whatever relays you have set up to gather this info. fukkin honeypot
daniele's avatar daniele
Say hello to Nstart, Nostr's onbarding tool! image Nstart aims to guide new users to Nostr offering a easy and no-nonsense onboarding wizard, with useful hints about the protocol and some really exclusive features: - Easy local backup of your nsec or ncryptsec - Email yourself your ncryptsec, as additional backup location - Create a multi-signer bunker URL for Nostr Connect (more info below) - Auto follow the contacts list of some old and trusted Nostr users - Customize of contact suggestions, useful for onboarding friends & family Try Nstart live at https://start.njump.me or watch the video below to understand how it works. A note about the multi-signer bunker. This is really cool stuff made by @fiatjaf, that uses FROST to split your nsec in 3 (or more) and distribute each shard to an independent trusted remote signer. This will give you a bunker code that you can use to log in to many web, mobile and desktop apps without exposing your nsec. If you ever lose your bunker code, if the signers vanish from Earth, and it stops working, or if it gets stolen by a malware virus, you can use your nsec to create a new one and invalidate the old one. More info and source code: Enjoy it and send back any feedback!
View quoted note →
Thank you for working on this! I wanted to try FROST but can't login with it, probably because I got a bunker string w/ promenade.fiatjaf.com as relay, and that relay requires auth to read, so subscription on replies gets CLOSED. Am I doing something wrong?
🛡️
Hey @Npub.pro Wondering if this could be integrated into nostr login on npub pro sites .
daniele's avatar daniele
Say hello to Nstart, Nostr's onbarding tool! image Nstart aims to guide new users to Nostr offering a easy and no-nonsense onboarding wizard, with useful hints about the protocol and some really exclusive features: - Easy local backup of your nsec or ncryptsec - Email yourself your ncryptsec, as additional backup location - Create a multi-signer bunker URL for Nostr Connect (more info below) - Auto follow the contacts list of some old and trusted Nostr users - Customize of contact suggestions, useful for onboarding friends & family Try Nstart live at https://start.njump.me or watch the video below to understand how it works. A note about the multi-signer bunker. This is really cool stuff made by @fiatjaf, that uses FROST to split your nsec in 3 (or more) and distribute each shard to an independent trusted remote signer. This will give you a bunker code that you can use to log in to many web, mobile and desktop apps without exposing your nsec. If you ever lose your bunker code, if the signers vanish from Earth, and it stops working, or if it gets stolen by a malware virus, you can use your nsec to create a new one and invalidate the old one. More info and source code: Enjoy it and send back any feedback!
View quoted note →
🛡️
Sure, the follows suggestions are absolutely optional, the user have to actively select them. But you can customize them to apply personalized follows, for example you can share: https://start.njump.me?s=npub1cwhy4k8qd2guyqz8t45u4yzyp4k4fhnjn573ukh6e77mde2dgm9s2lujc5 And your friend will find your profile, pre-selected, in the final follows proposal. You can also add more profiles, separating them with commas.
🛡️
Nstart suggests some old and trusted users, but in the end it copies their following list, so we choose the initial limited selection but actually these people create the final lists. In the future I will probably add some sort of "starter packs", that will also include coated selections by countries or languages. To achieve what you want now, as suggested you can add one more npubs (separated by commas). You can also trick the system: create a fictional "French community" user and use it to follow a bunch of people, then add it to the suggestions!
Que pensez vous de cette idée pour un nouveau ?
daniele's avatar daniele
Say hello to Nstart, Nostr's onbarding tool! image Nstart aims to guide new users to Nostr offering a easy and no-nonsense onboarding wizard, with useful hints about the protocol and some really exclusive features: - Easy local backup of your nsec or ncryptsec - Email yourself your ncryptsec, as additional backup location - Create a multi-signer bunker URL for Nostr Connect (more info below) - Auto follow the contacts list of some old and trusted Nostr users - Customize of contact suggestions, useful for onboarding friends & family Try Nstart live at https://start.njump.me or watch the video below to understand how it works. A note about the multi-signer bunker. This is really cool stuff made by @fiatjaf, that uses FROST to split your nsec in 3 (or more) and distribute each shard to an independent trusted remote signer. This will give you a bunker code that you can use to log in to many web, mobile and desktop apps without exposing your nsec. If you ever lose your bunker code, if the signers vanish from Earth, and it stops working, or if it gets stolen by a malware virus, you can use your nsec to create a new one and invalidate the old one. More info and source code: Enjoy it and send back any feedback!
View quoted note →
Yes at the end. Why are clients being forced to support multi sig? Thought this was for new users, not privacy and security OGs? Had a buddy totally new through it and he's not a fan. He'd like to just be able to use nostr, not go through a bunch what he calls "unnecessary steps that make no sense to him". 🤷 We ended up just installing amethyst and minibits after.
🛡️
These bunkers are not for OGs, they are first of all for casual users that need a way to use Nostr without accidentally burn their nsec. At the same time they also protects from buggy software and malware. So in this first phase I'm specifically promoting apps that support this connection method. If your friend doesn't need these onboarding features he did very well to download his favorite client and create his account there. Remember him to backup his nsec.
It doesn't matter why your doing it. It's counter productive for onboarding new people to nostr. New users backing up(saving) their nsec(password in layman's terms) is enough. If the common social media user doesn't know how to protect and save their passwords for social accounts, thats on them. Running in with an extra step to play hero for their nsec(password) is not the way to get new users. Please read on Wisdom of Crowds. Basic nsec(password) backup and entry for log in and security is the median. Options above this should be sold separately for those who find value in it. Options below this and you wouldn't even have a nostr account.
🛡️
is it simple enough for my grandma? I let it create a bunker, and in final step I opened Coracle., but no guidance how to login in Coracle ? (I expected it all down automagically). I friend of mine tried to use Start and reported the window closed after downloading nsec file.
🛡️
One thing missing in the promenade description is that signers connect directly to the coordinator. In theory one could use a different relay as a proxy, but connecting directly is more private and more efficient and allows coordinators to know which signers are online. Currently events shared between coordinator and signers are not encrypted in any way.
🛡️
What do you mean? They are multi-party. Promenade is two things: a coordinator and the signers. There are currently 5 signers I think, ran by different people. The client (nstart) will select 3 of these at random to do a 2of3 scheme (I think ideally it would be a 3of4 or maybe 3of3 if we get very reliable signers). The client can in theory select any signers they want and any coordinator they want, but currently it's all hardcoded because we don't have anyone else interested (do you want to run a signer and be added to list, by the way?) and I don't know what would be the UX of giving people options. @daniele is working on a "manager" client companion to nstart that I think will give the user ways to configure these things. In the future (always in the future) we may have a more decentralized market of coordinators and signers and friend recommendations and stuff like that.
🛡️
Oh, unrelated but also if you compromise your bunker currently you can delete it from the coordinator so the coordinator will just stop answering to requests for that specific bunker URL. Or you can redo the bunker setup process with the same signers and coordinator and your previous stuff will be deleted and overwritten. For this you need your main nsec.
Well I meant "hey are you running signers yourself for now?", but it's great to know those are different people - found the list on nstart source. Happy to run it too: @npub1qaek...0kuu The UX of giving people options could probably look like "Choose 3 of these 10 signers passing wot score threshold" with some defaults set. Signer owners should put their signature somewhere (nip89 event?) to enable that. How do I ask coordinator to delete the bunker url?
App either has hard-coded pubkeys of trusted owners, or trusted "wot root" pubkeys, or may infer some context from the place where user is signing up. I.e. if user signs up on npub.pro site then we'll use site admin as wot root (we already reuse their relays for new profile, and suggest new user to follow them). Even if wot roots or owners are hard-coded I guess it's better then hardcoded signer pubkeys bcs new good signers can be discovered/suggested without recompiling the app.
🛡️
Interesting stuff. Did you see this?
daniele's avatar daniele
Say hello to Nstart, Nostr's onbarding tool! image Nstart aims to guide new users to Nostr offering a easy and no-nonsense onboarding wizard, with useful hints about the protocol and some really exclusive features: - Easy local backup of your nsec or ncryptsec - Email yourself your ncryptsec, as additional backup location - Create a multi-signer bunker URL for Nostr Connect (more info below) - Auto follow the contacts list of some old and trusted Nostr users - Customize of contact suggestions, useful for onboarding friends & family Try Nstart live at https://start.njump.me or watch the video below to understand how it works. A note about the multi-signer bunker. This is really cool stuff made by @fiatjaf, that uses FROST to split your nsec in 3 (or more) and distribute each shard to an independent trusted remote signer. This will give you a bunker code that you can use to log in to many web, mobile and desktop apps without exposing your nsec. If you ever lose your bunker code, if the signers vanish from Earth, and it stops working, or if it gets stolen by a malware virus, you can use your nsec to create a new one and invalidate the old one. More info and source code: Enjoy it and send back any feedback!
View quoted note →