block / block/buzz

Data consistency and security recovery

Open
#3,718 0 comments 2 reactions 0 assignees View on GitHub
Dominant language
Rust
Stars
32.7k
Forks
4.3k
Avg merge
1d 13h
Merged PRs (30d)
253

Description

Can someone from the team quickly explain how data recovery works since it's based on the Nostr protocol? There is no information on this anywhere.

What happens if your main key or team/agents private keys gets leaked. Or you need to rotate them for security?

From what I understand this is not possible and means all your data is permanently gone. Unless I'm missing something, and you can link the cryptographic keys to an external authentication data point in a self-hosted setup or third party relay.

Worse case scenario but possible in today's world. What happens if someone gets a private key? Not being able to revoke or change is pretty much a security nightmare. I understand the project is quite new, but there are important questions to scale from a hobby project to being used for real work. The initial setup is all publicly exposed which is understandable from a community project. But for self-hosted private instances there are real concerns based on the sensitive information and the amount of data this can potentially host.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.