Post by utxo detective

1N6JkY…aXBL Unverified · twetch

I was green in the blast of the past. I am not at this moment in time.

I think I need a way to login with username and password, it makes the login feel safer.

Maybe skip username/password and go directly for passkey support. I don't want to "type" or "copy/paste" in my seed anywhere tbh, but one exposure in what I redeem a safe environment would be ok, to generate the passkey that I can use safely on all devices.

Not sure how this would work with signing, but I am sure it's just a link somehow to the passkey.

Seed exposure (human opening it up to use) for only very controlled environments.

Elon Moist (CEO) 2mo

what would convince you?

311 162 sat
12tDnc…Cn4W Unverified · twetch

I’ve been looking into pass keys and it seems like there are two options

  1. The pass key securely derives, a deterministic but random seed phrase. This works fully client side and would let you create and account without needing to write down the words
  2. A pass key encrypts your current seed phrase, and we would save the encrypted on twetch servers

I like #1 better, but for existing users it would mean migrating from current seed to a passkey one

625 488 sat
What the chain says
Block
960 905
Time
2026-08-05T02:50:07Z
Signer
12tDncQvFZaZzqanupmtXpDUm42Wd4Cn4W
App
twetch
Type
reply
Content type
text/markdown

Fields the transaction did not carry are omitted. Open the payload to see the bytes as stored.

Signed by 12tDncQvFZaZzqanupmtXpDUm42Wd4Cn4W Unverified

Replies (3)

1MsA8b…3dg3 Unverified · twetch
Replying to@12tDnc…Cn4W

migrate bad

624 513 sat
1F8Amr…k9WW Unverified · twetch
Replying to@12tDnc…Cn4W

Maybe base on human dna. A little finger prick each login.

I have no idea what I’m talking about

1N6JkY…aXBL Unverified · twetch
Replying to@12tDnc…Cn4W

Option 2 it is then, with maybe a passkey.twetch.com instance that runs separately the code that is fully inspectable in browser (or any other tool) and domain originated with https load, to then input seed, get passkey (generates safely on device) and ready.

With some smart revoke + re-encrypt and find the balance of where "session" ends for good security and good user interface. Most won't mind the quick few seconds to login again with a passkey.

You guys are the experts, you decide. Love to see something like it and have Twetch securely available anywhere at anytime.