Skip to content

Data consistency and security recovery #3718

Description

@SyntaxDreamer

Can someone from the team quickly explain how data recovery works since it's based on the Nostr protocol? There is no information on this anywhere.

What happens if your main key or team/agents private keys gets leaked. Or you need to rotate them for security?

From what I understand this is not possible and means all your data is permanently gone. Unless I'm missing something, and you can link the cryptographic keys to an external authentication data point in a self-hosted setup or third party relay.

Worse case scenario but possible in today's world. What happens if someone gets a private key? Not being able to revoke or change is pretty much a security nightmare. I understand the project is quite new, but there are important questions to scale from a hobby project to being used for real work. The initial setup is all publicly exposed which is understandable from a community project. But for self-hosted private instances there are real concerns based on the sensitive information and the amount of data this can potentially host.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions