Thanks, I think I may have found the pomegranate repo here:

npub16xnpfx85k8wzdhctang6860g3u64lds5kac73ddjwlg0lxdg9g3su56z6l
hex
c75db6a3000105fdeee2d2f84bfa7f8d1dd7a7f99906c6f478bbc98efa379ff7nevent
nevent1qqsvwhdk5vqqzp0aam3d97ztlflc68wh5luejpkx73uthjvwlgmelacprpmhxue69uhhyetvv9ujuem4d36kwatvw5hx6mm9qgsdrfs5nr6trhpxmu97e5dra85g7d2lkc2twu0gkke8058lnx5z5gcyjqlceKind-1 (TextNote)
↳ Reply to Event not found
7d90caaf9b942ebfdf42a112ccc57d20575453ca7f4da6f00c65e5307d27d0d8...
Thanks, I think I may have found the pomegranate repo here:
https://gitworkshop.dev/npub180cvv07tjdrrgpa0j7j7tmnyl2yr6yr7l8j4s3evf6u64th6gkwsyjh6w6/relay.ngit.dev/pomegranate
I'm trying to understand the security posture.
It seems that the user, for each generation of key shards G that they produce, sets a threshold number T(G) such that anyone who at any time holds at least T(G) distinct shards from generation G will be able to reconstruct the user's privkey.
If that's correct, it seems that
-
Google itself can get your privkey at any time if they decide to fake OAuth;
-
anyone who has your Google login credentials will be able to get your privkey;
-
if at least T(G) operators holding shards of generation G collude, they will be able to get your privkey;
-
if anyone is able to steal at least T(G) shards of generation G from operators, they will be able to get your privkey;
-
any combination of dishonest operators and thieves that together at any future time come to hold at least T(G) shards of generation G will be able to get your privkey.
Does that seem right?
Raw JSON
{
"kind": 1,
"id": "c75db6a3000105fdeee2d2f84bfa7f8d1dd7a7f99906c6f478bbc98efa379ff7",
"pubkey": "d1a61498f4b1dc26df0becd1a3e9e88f355fb614b771e8b5b277d0ff99a82a23",
"created_at": 1788866007,
"tags": [
[
"e",
"0bb4daf107c109410d85a15391dd4961e47fa97cfc7d35f83c1a1df0bb44d531",
"wss://nostr.mom/",
"root",
"50d94fc2d8580c682b071a542f8b1e31a200b0508bab95a33bef0855df281d63"
],
[
"e",
"7d90caaf9b942ebfdf42a112ccc57d20575453ca7f4da6f00c65e5307d27d0d8",
"wss://nostr.wine/",
"reply",
"3bf0c63fcb93463407af97a5e5ee64fa883d107ef9e558472c4eb9aaaefa459d"
],
[
"p",
"3bf0c63fcb93463407af97a5e5ee64fa883d107ef9e558472c4eb9aaaefa459d"
]
],
"content": "Thanks, I think I may have found the pomegranate repo here:\n\nhttps://gitworkshop.dev/npub180cvv07tjdrrgpa0j7j7tmnyl2yr6yr7l8j4s3evf6u64th6gkwsyjh6w6/relay.ngit.dev/pomegranate\n\nI'm trying to understand the security posture.\n\nIt seems that the user, for each generation of key shards G that they produce, sets a threshold number T(G) such that anyone who at any time holds at least T(G) distinct shards from generation G will be able to reconstruct the user's privkey.\n\nIf that's correct, it seems that\n\n1. Google itself can get your privkey at any time if they decide to fake OAuth;\n\n2. anyone who has your Google login credentials will be able to get your privkey;\n\n3. if at least T(G) operators holding shards of generation G collude, they will be able to get your privkey;\n\n4. if anyone is able to steal at least T(G) shards of generation G from operators, they will be able to get your privkey;\n\n5. any combination of dishonest operators and thieves that together at any future time come to hold at least T(G) shards of generation G will be able to get your privkey.\n\nDoes that seem right?",
"sig": "41d3ebea5c5912685641e43097a1c4a2eb211c05c446d5d156b93eb8fed15f12ccc0a06cf5b0a7b69e0261edfe3d306071a34eed3136c73f41bda6e12f46254d"
}