If you are using Android, the only place you should paste you nsec is on Amber. No other app cares about your key security as Amber does. No one.
Thread
Login to reply
Replies (51)
key cares one. If is Amber. No as paste about place you you using Amber only the other on app your security you does. nsec are No should Android,
What's amber?
A signer app for Android. You can find it on zap store
At the risk of sounding retarded, what's zapstore?
Our own app store: https://zapstore.dev/
Some AppStore alternative for Nostr/Bitcoin apps, i think. I've never used it, and i don't know what are the pros of using it over Obtanium(with Github repo links).
Dis is hooje mah bruddah
🙏
Obtainium works like Twitter. You can access a lot of content - but it lives on a centralized platform and it's not cryptographically signed.
Zapstore brings the concept of nostr-signing software releases, so you can verify them just like your client verifies regular notes.
And... you can zap them.
lol
Huh?! Obtainium doesn't work like Twitter. You mean the source code of Obtainium is on a centralized platform, like the source code of Zapstore? Obtainium is signed and you can verify it with AppVerifier (like Zapstore).
No, I did not mean that. I am talking about the content.
I missed the «it» — sorry for that!
I will be full time zapstore when I can (automatically) export my app list to a file like obtanium does. I have automation that backs up that file to my next cloud server and then mirrors the repo on my Gitea instance. But it's purely my personal opinion that mirroring is more important than signed apps at this exact moment in time with microsofts bs github policies.
That will come with
as private bookmarks with all user's installed apps. You could then use nak in your automation to pull the event, decrypt and grab the repositories
GitHub
Privately bookmarked apps · Issue #160 · zapstore/zapstore
button to favourite apps without installing them yet
Lit, tried to zap but I think the WiFi here is blocking it.
No worries! Thanks for the patience
OFFLINE-version of Amber*
Even better
#tno
trust no one.
If you are using Android, the only place you should paste you nsec is on Amber. No other app cares about your key security as Amber does. No one.
View quoted note →
Tried keychat?
Yep, not a big fan. They do a bunch of things without creating any NIPs that we can integrate with. I prefer 0xchat.
I meant as a browser for mini web apps? They support nip07 which makes it extremely easy to test out a lot of web apps without the inconvenience of bunkers. They have gone a long way from just a messaging app
I would never insert my nsec in any app that has a browser inside of it. Ever.
You could test it out with a test nsec to actually see how it works. We all inserted our nsecs in amethyst before amber became the norm. They are actually moving in the right direction
They support amber as well. 

Cool, then you don't need the inner browser. You can just run it on a regular browser if they support nip55
This is just to create an identity. The identity is what is used with the mini apps with nip07. Again it would be great if you tested it out to see what they have been cooking
Will do some tests.
This is why nostr isn't growing....
I need 4 apps just to use nostr. And even then on mobile "no extention found" for 85% of things built.
Extensions don't work on mobile browsers. They have to support nip55 to get Amber to sign.
Try out #keychat. One app to test all the mini web apps with support for multiple accounts and different login methods.
Kiwi browser did it before it shut down. Lemur browser has extensions but never pops up to sign on. Hopefully they fix that.
What's best practice on iOS, do you know? Getting ready for @Shosho – Live Stream on Nostr iOS release but not sure what is best to support.
Let's hope they can do it. iOS is not the best place for app to app communication. :(
Very cool.. too bad that it is multiplatform.
Nem o Amethyst? Que coisa não...
Sim. We do too many things on Amethyst. Amber has a flavor that it can't even connect to the Internet.
What does the Amber do/care that Amethyst or other apps do not?
Amber is not a Nostr client that you use to browse content. Amber helps secure your nsec so no one gets access to it.
Let's say you download several Nostr clients (one for browsing written content, one for video, one for voice chat, etc etc). Withoug Amber you would have to give each of those clients youe nsec so that the client can use it to sign the events (posts) that you post through it (that way people know it's from you).
What if one of more of those clients is malicious and shares your nsec with others? What if it's insecurily voded and hackers get access to your nsec through it. The more clients you give your nsec to, the larger the risk.
With Amber (and clients that support it) you DON'T give your nsec to any other client to sign into it. Instead you tell the client to use Amber to sign your posts/events with. So Amber is the ONLY app that knows your nsec. Other apps get hacked, they still can't give hackers your nsec because they don't have it.
Makes sense?
#nostr #grownostr #amber
Why isn’t amber on iOS? Does it have to do with #apple ecosystem?
Apple doesn't allow anything like that.
Sucks to be using the iPhone
Stop using it.
I make accounts on every site. I'm not a fan of using one nsec everywhere. It's safer and less confusing.
I use amber sometimes but it's confusing. I'm just gonna keep a backups of my notes using citrine so if someday my nsec gets stolen I can import all my notes to my new nsec.
That works as well.
@Satlantis: The Social Events App wink wink nudge nudge
Can you explain to non app developers why nostr clients can't do what Amber does. To play devil's advocate if I only use Amethyst on nostr can I not think of that as an Amber that also posts? Or is Amber somehow more secure?
Most devs don't have the knowledge and/or time and resources to protect your keys well. This is especially true if they are shipping apps to all operating systems.
Amber focuses only on that and doesn't do anything else. There is a version of Amber isn't even authorized by Android to use the Internet.