# Nostr Private Key Security Guide

## Understanding Nostr Keys

| Key | Format | Purpose |
|-----|--------|---------|
| **Private Key** | `nsec1...` (32 bytes, bech32 encoded) | Signs all your actions — **NEVER SHARE** |
| **Public Key** | `npub1...` | Your identity — safe to share |
| **NIP-05** | `user@domain.com` | Human-readable identity verification |

**Critical:** If someone gets your `nsec`, they control your identity. There's no password reset in Nostr.

---

## Security Hierarchy (Most → Least Secure)

### 1. Hardware Signers (Best)
**Air-gapped devices that sign without exposing your key to the internet.**

| Device | Platform | Notes |
|--------|----------|-------|
| **Nostr Signing Device** | DIY (ESP32) | Air-gapped, USB signing |
| **Nsec Remote Signer** | Dedicated hardware | £39.99, remote signing |
| **Trezor/Ledger** | Hardware wallets | Limited Nostr support |
| **OneKey** | Hardware wallet | Full Nostr Signing Device support |

**Pros:** Key never touches internet, malware can't steal it
**Cons:** Expensive, less convenient, requires physical device

---

### 2. Mobile Signers (Recommended for Most Users)
**Dedicated apps that hold your key and sign requests from other apps.**

| App | Platform | How It Works |
|-----|----------|--------------|
| **Amber** | Android | Signs for other Nostr apps via intent system |
| **Aegis** | iOS | Dedicated signer with remote signing support |

**Pros:** Convenient, key stays in one app, approve each action
**Cons:** Phone can be lost/stolen

---

### 3. Browser Extensions (Good for Desktop)
**Extensions that sign for web clients without exposing your key to websites.**

| Extension | Browser | Features |
|-----------|---------|----------|
| **Alby** | Chrome, Firefox, Brave | Nostr + Lightning wallet |
| **nos2x** | Chrome, Firefox | Simple Nostr signer |
| **Nostore** | Chrome, Firefox | Focus on key storage |
| **Nostash** | Chrome, Firefox, Safari | Open source, encrypted storage, popup signing |
| **Keypal / Nostore** | Safari | iOS & macOS extension |
| **nsec.app** | Web-based | Remote signer, syncs devices |

**How it works:**
1. Install extension
2. Import/create key in extension
3. Websites request signature → Extension prompts you → Key never leaves extension

**Pros:** Easy to use, works across web clients
**Cons:** Browser vulnerabilities, computer can be compromised

---

#### Nostash Deep Dive
**Modern, open-source browser extension for Nostr key management.**

**Key Features:**
- 🔐 **Encrypted Storage**: Keys encrypted at rest in browser
- 🔔 **Popup Signing**: Approval popup for every signature request
- 🌐 **Multi-Client**: Works with Damus, Iris, Snort, Primal, and other web clients
- 📱 **Backup**: Secure export/import with encrypted backup
- 🔓 **Open Source**: github.com/kind-quest/nostash

**Browser Support:**
| Platform | Support |
|----------|---------|
| Chrome | ✅ Official |
| Firefox | ✅ Official |
| Safari | ✅ Official |
| Brave | ✅ Compatible |

**Setup:**
1. Install from Chrome Web Store / Firefox Add-ons / Safari Extensions
2. Create new key or import existing nsec
3. Set encryption password
4. Connect to web clients via NIP-07 (browser extension standard)

**Security Notes:**
- Keys encrypted with user-provided password (AES-256)
- Never transmits private keys to websites
- Signs locally in extension
- No server component, fully local

---

### 4. Remote Signers (nsecBunker)
**Self-hosted signing server for power users.**

**Setup:**
- Run `nsecBunker` on a server or local machine
- Stores encrypted keys
- Other clients connect via NIP-46 (remote signing)
- Admin UI for key management

**Pros:** Multi-device access, centralized key management
**Cons:** Technical setup, server must be secured

---

### 5. Password Managers (Acceptable Backup)
**Encrypted storage in password managers.**

**Recommended:**
- 1Password (recommended by nostr.how)
- Bitwarden (open source)
- KeePassXC (offline, open source)

**Best Practices:**
```
Entry Type: Secure Note (NOT password field)
Content:
---
Nostr Private Key (NEVER SHARE)
nsec: nsec1...your...key...here

Public Key (safe to share)
npub: npub1...your...key...here

Created: 2025-02-15
Used for: [primary identity]
---
```

**Pros:** Encrypted, backed up, cross-device
**Cons:** Clipboard exposure when pasting, not air-gapped

---

## OS-Specific Best Practices

### macOS

| Method | Security Level | Recommendation |
|--------|---------------|----------------|
| **Keychain** | Medium | Better than plaintext, but clipboard exposure |
| **Browser Extension** | Good | Alby or nos2x recommended |
| **Hardware Signer** | Best | Use Nostr Signing Device or OneKey |
| **Password Manager** | Good | 1Password, Bitwarden |

**macOS Keychain approach:**
1. Store `nsec` in a Secure Note in Keychain Access
2. Or use a password manager
3. **Never** store in Notes, TextEdit, or desktop files

**Warning:** macOS clipboard is accessible to apps running in background.

---

### Windows

| Method | Security Level | Recommendation |
|--------|---------------|----------------|
| **BitLocker + Password Manager** | Good | Encrypt drive, use Bitwarden |
| **Hardware Signer** | Best | Works well on Windows |
| **Browser Extension** | Good | Alby or nos2x |
| **Windows Credential Manager** | Medium | Better than nothing |

**Required:**
- Enable BitLocker (full disk encryption)
- Use a password manager (not Credential Manager alone)

---

### Linux

| Method | Security Level | Recommendation |
|--------|---------------|----------------|
| **Encrypted Home (LUKS)** | Good | Full disk encryption required |
| **Hardware Signer** | Best | DIY Nostr Signing Device works well |
| **Pass (password-store)** | Good | GPG-encrypted, CLI-based |
| **Browser Extension** | Good | Alby or nos2x |
| **KeePassXC** | Good | Offline, encrypted database |

**Linux-specific tools:**
- `pass` - GPG-encrypted password store
- `gpg-agent` for key caching
- `secret-tool` (libsecret) for GNOME keyring

---

### Android

| Method | Security Level | Recommendation |
|--------|---------------|----------------|
| **Amber** | Best | Purpose-built, signs for other apps |
| **Hardware Signer** | Best | Nsec Remote Signer |
| **Password Manager** | Good | Bitwarden, Keepass2Android |

**Amber (Recommended):**
1. Install Amber from F-Droid or Play Store
2. Import your nsec
3. Other Nostr apps (Primal, Amethyst) use Amber to sign
4. Key never leaves Amber

---

### iOS

| Method | Security Level | Recommendation |
|--------|---------------|----------------|
| **Aegis** | Best | Dedicated signer (remote signing via TestFlight/stable) |
| **Safari Extension** | Good | Native Nostr signer extension for Safari |
| **Built-in (Primal, etc)** | Medium | Client apps with integrated key storage |
| **Hardware Signer** | Best | Works via browser |
| **Password Manager** | Good | 1Password, Bitwarden |

**Key options:**
- **Aegis:** Purpose-built iOS signer with remote signing capabilities
- **Primal:** Has built-in key management (no separate signer needed)
- **Safari Extension (Keypal/Nostore/Nostash):** Native browser signing for web clients
  - **Nostash Safari:** Encrypted key storage, popup signing for web clients
  - **Keypal:** Simple Safari extension for Nostr signing
- **TestFlight apps:** Early access to new signer features

**Note:** Unlike Android's Amber, iOS apps cannot share keys between each other due to sandboxing. Each app manages its own key storage unless using a signer app like Aegis.

---

## Physical Backup (Always Recommended)

### Paper Backup (Basic)
1. Write `nsec` on paper
2. Store in fireproof safe
3. Consider metal backup (fireproof)
4. Multiple locations

### Metal Backup (Best)
- Steel plate engraving
- Fireproof, waterproof
- Products: Cryptosteel, Billfodl

### Shamir's Secret Sharing (Advanced)
- Split key into N parts
- Require M parts to reconstruct
- Example: 3-of-5 shares
- Distribute to trusted contacts/locations

---

## What NEVER To Do

| ❌ Bad Practice | Why |
|----------------|-----|
| Store `nsec` in plaintext file | Malware can read it |
| Save in Notes/TextEdit | Unencrypted |
| Email it to yourself | Email is not secure |
| Message it on Telegram/Discord | Not end-to-end encrypted for storage |
| Paste into multiple web clients | Each client is an attack vector |
| Share with "support" | Nobody needs your nsec — ever |
| Screenshot it | Photos sync to cloud |
| Store in browser localStorage | XSS attacks can steal it |

---

## Security Tiers Summary

| Tier | Method | For Who |
|------|--------|---------|
| **1 (Best)** | Hardware signer | High-value accounts, tech-savvy users |
| **2** | Mobile signer (Amber/Aegis) | Most users with phones |
| **3** | Browser extension | Desktop-heavy users |
| **4** | Password manager | Backup + convenience |
| **5** | Physical backup | Everyone (offline insurance) |

---

## Recommended Setup for Most Users

```
┌─────────────────────────────────────────────────────────────┐
│                    RECOMMENDED SETUP                         │
├─────────────────────────────────────────────────────────────┤
│  Primary:   Mobile signer (Amber on Android, Aegis on iOS)  │
│  Secondary: Browser extension (Alby/Safari) for desktop   │
│  Backup:    Paper/metal backup in secure location           │
│  Digital:   Password manager (encrypted secure note)        │
├─────────────────────────────────────────────────────────────┤
│  Key rotation: Create backup BEFORE using anywhere          │
│  Test: Verify backup works by restoring on another device │
└─────────────────────────────────────────────────────────────┘
```

---

## Resources

- **Nostr Signing Device:** https://nostrsigningdevice.com/
- **Amber (Android):** https://github.com/greenart7c3/Amber
- **Alby:** https://getalby.com/
- **nos2x:** https://github.com/fiatjaf/nos2x
- **nsecBunker:** https://github.com/kind-0/nsecbunker
- **nsec.app:** https://nsec.app/
- **Key Management Guide:** https://nostr.co.uk/learn/key-management/
- **Soapbox Key Guide:** https://soapbox.pub/blog/managing-nostr-keys

---

*Last updated: February 19, 2026*
*Corrections: iOS section updated (Aegis replaces diVine, added Safari extensions, TestFlight note)*