Kihagyás

Nostr Private Key Security Guide

Understanding Nostr Keys

Key Format Purpose
Private Key nsec1... (32 bytes, bech32 encoded) Signs all your actions — NEVER SHARE
Public Key npub1... Your identity — safe to share
NIP-05 user@domain.com Human-readable identity verification

Critical: If someone gets your nsec, they control your identity. There's no password reset in Nostr.


Security Hierarchy (Most → Least Secure)

1. Hardware Signers (Best)

Air-gapped devices that sign without exposing your key to the internet.

Device Platform Notes
Nostr Signing Device DIY (ESP32) Air-gapped, USB signing
Nsec Remote Signer Dedicated hardware £39.99, remote signing
Trezor/Ledger Hardware wallets Limited Nostr support
OneKey Hardware wallet Full Nostr Signing Device support

Pros: Key never touches internet, malware can't steal it Cons: Expensive, less convenient, requires physical device


Dedicated apps that hold your key and sign requests from other apps.

App Platform How It Works
Amber Android Signs for other Nostr apps via intent system
Aegis iOS Dedicated signer with remote signing support

Pros: Convenient, key stays in one app, approve each action Cons: Phone can be lost/stolen


3. Browser Extensions (Good for Desktop)

Extensions that sign for web clients without exposing your key to websites.

Extension Browser Features
Alby Chrome, Firefox, Brave Nostr + Lightning wallet
nos2x Chrome, Firefox Simple Nostr signer
Nostore Chrome, Firefox Focus on key storage
Nostash Chrome, Firefox, Safari Open source, encrypted storage, popup signing
Keypal / Nostore Safari iOS & macOS extension
nsec.app Web-based Remote signer, syncs devices

How it works: 1. Install extension 2. Import/create key in extension 3. Websites request signature → Extension prompts you → Key never leaves extension

Pros: Easy to use, works across web clients Cons: Browser vulnerabilities, computer can be compromised


Nostash Deep Dive

Modern, open-source browser extension for Nostr key management.

Key Features: - 🔐 Encrypted Storage: Keys encrypted at rest in browser - 🔔 Popup Signing: Approval popup for every signature request - 🌐 Multi-Client: Works with Damus, Iris, Snort, Primal, and other web clients - 📱 Backup: Secure export/import with encrypted backup - 🔓 Open Source: github.com/kind-quest/nostash

Browser Support: | Platform | Support | |----------|---------| | Chrome | ✅ Official | | Firefox | ✅ Official | | Safari | ✅ Official | | Brave | ✅ Compatible |

Setup: 1. Install from Chrome Web Store / Firefox Add-ons / Safari Extensions 2. Create new key or import existing nsec 3. Set encryption password 4. Connect to web clients via NIP-07 (browser extension standard)

Security Notes: - Keys encrypted with user-provided password (AES-256) - Never transmits private keys to websites - Signs locally in extension - No server component, fully local


4. Remote Signers (nsecBunker)

Self-hosted signing server for power users.

Setup: - Run nsecBunker on a server or local machine - Stores encrypted keys - Other clients connect via NIP-46 (remote signing) - Admin UI for key management

Pros: Multi-device access, centralized key management Cons: Technical setup, server must be secured


5. Password Managers (Acceptable Backup)

Encrypted storage in password managers.

Recommended: - 1Password (recommended by nostr.how) - Bitwarden (open source) - KeePassXC (offline, open source)

Best Practices:

Entry Type: Secure Note (NOT password field)
Content:
---
Nostr Private Key (NEVER SHARE)
nsec: nsec1...your...key...here

Public Key (safe to share)
npub: npub1...your...key...here

Created: 2025-02-15
Used for: [primary identity]
---

Pros: Encrypted, backed up, cross-device Cons: Clipboard exposure when pasting, not air-gapped


OS-Specific Best Practices

macOS

Method Security Level Recommendation
Keychain Medium Better than plaintext, but clipboard exposure
Browser Extension Good Alby or nos2x recommended
Hardware Signer Best Use Nostr Signing Device or OneKey
Password Manager Good 1Password, Bitwarden

macOS Keychain approach: 1. Store nsec in a Secure Note in Keychain Access 2. Or use a password manager 3. Never store in Notes, TextEdit, or desktop files

Warning: macOS clipboard is accessible to apps running in background.


Windows

Method Security Level Recommendation
BitLocker + Password Manager Good Encrypt drive, use Bitwarden
Hardware Signer Best Works well on Windows
Browser Extension Good Alby or nos2x
Windows Credential Manager Medium Better than nothing

Required: - Enable BitLocker (full disk encryption) - Use a password manager (not Credential Manager alone)


Linux

Method Security Level Recommendation
Encrypted Home (LUKS) Good Full disk encryption required
Hardware Signer Best DIY Nostr Signing Device works well
Pass (password-store) Good GPG-encrypted, CLI-based
Browser Extension Good Alby or nos2x
KeePassXC Good Offline, encrypted database

Linux-specific tools: - pass - GPG-encrypted password store - gpg-agent for key caching - secret-tool (libsecret) for GNOME keyring


Android

Method Security Level Recommendation
Amber Best Purpose-built, signs for other apps
Hardware Signer Best Nsec Remote Signer
Password Manager Good Bitwarden, Keepass2Android

Amber (Recommended): 1. Install Amber from F-Droid or Play Store 2. Import your nsec 3. Other Nostr apps (Primal, Amethyst) use Amber to sign 4. Key never leaves Amber


iOS

Method Security Level Recommendation
Aegis Best Dedicated signer (remote signing via TestFlight/stable)
Safari Extension Good Native Nostr signer extension for Safari
Built-in (Primal, etc) Medium Client apps with integrated key storage
Hardware Signer Best Works via browser
Password Manager Good 1Password, Bitwarden

Key options: - Aegis: Purpose-built iOS signer with remote signing capabilities - Primal: Has built-in key management (no separate signer needed) - Safari Extension (Keypal/Nostore/Nostash): Native browser signing for web clients - Nostash Safari: Encrypted key storage, popup signing for web clients - Keypal: Simple Safari extension for Nostr signing - TestFlight apps: Early access to new signer features

Note: Unlike Android's Amber, iOS apps cannot share keys between each other due to sandboxing. Each app manages its own key storage unless using a signer app like Aegis.


Paper Backup (Basic)

  1. Write nsec on paper
  2. Store in fireproof safe
  3. Consider metal backup (fireproof)
  4. Multiple locations

Metal Backup (Best)

  • Steel plate engraving
  • Fireproof, waterproof
  • Products: Cryptosteel, Billfodl

Shamir's Secret Sharing (Advanced)

  • Split key into N parts
  • Require M parts to reconstruct
  • Example: 3-of-5 shares
  • Distribute to trusted contacts/locations

What NEVER To Do

❌ Bad Practice Why
Store nsec in plaintext file Malware can read it
Save in Notes/TextEdit Unencrypted
Email it to yourself Email is not secure
Message it on Telegram/Discord Not end-to-end encrypted for storage
Paste into multiple web clients Each client is an attack vector
Share with "support" Nobody needs your nsec — ever
Screenshot it Photos sync to cloud
Store in browser localStorage XSS attacks can steal it

Security Tiers Summary

Tier Method For Who
1 (Best) Hardware signer High-value accounts, tech-savvy users
2 Mobile signer (Amber/Aegis) Most users with phones
3 Browser extension Desktop-heavy users
4 Password manager Backup + convenience
5 Physical backup Everyone (offline insurance)

┌─────────────────────────────────────────────────────────────┐
│                    RECOMMENDED SETUP                         │
├─────────────────────────────────────────────────────────────┤
│  Primary:   Mobile signer (Amber on Android, Aegis on iOS)  │
│  Secondary: Browser extension (Alby/Safari) for desktop   │
│  Backup:    Paper/metal backup in secure location           │
│  Digital:   Password manager (encrypted secure note)        │
├─────────────────────────────────────────────────────────────┤
│  Key rotation: Create backup BEFORE using anywhere          │
│  Test: Verify backup works by restoring on another device │
└─────────────────────────────────────────────────────────────┘

Resources

  • Nostr Signing Device: https://nostrsigningdevice.com/
  • Amber (Android): https://github.com/greenart7c3/Amber
  • Alby: https://getalby.com/
  • nos2x: https://github.com/fiatjaf/nos2x
  • nsecBunker: https://github.com/kind-0/nsecbunker
  • nsec.app: https://nsec.app/
  • Key Management Guide: https://nostr.co.uk/learn/key-management/
  • Soapbox Key Guide: https://soapbox.pub/blog/managing-nostr-keys

Last updated: February 19, 2026 Corrections: iOS section updated (Aegis replaces diVine, added Safari extensions, TestFlight note)

Vissza a tetejére