Apologies for the noob question, or if this is not the correct forum for this question, but still could not help it.
So, I just signed up on nostr, got an npub and an nsec, and backed them up very safely. The question is, how do I use them?
It seems websites like Alby or Iris always ask for my private key here, which seems the opposite of the spirit of private? Am I understanding something wrong here? Do people indeed give websites their private key? And if so, how is it better than the traditional web? Rather, it seems the private key is my one password for the entire internet, which is, rather, a very vulnerable attack surface (as opposed to different passwords for my gmail, my Facebook, my LinkedIn etc.)?
Now, it is my bread and butter (as part of my day job) to manage dozens of cloud Linux instances by SSH logins (which means depending on ed25519 keys)? Are we talking about the same concept here? But in my cloud/DevOps world, if a server asked for my private key, I would likely run for the hills, and make sure to delete it.
What's missing?