Private messages aren’t private at all in the event of a key leak. There are safer ways to DM
Login to reply
Replies (2)
NIP44 does NOT leak key information, again you're talking about NIP04. Nobody should EVER use NIP04. We're talking about two different things
I think you guys are talking past each other a bit.
@Logen is not saying that NIP-44 leaks key data. His point is that if a user's private key is leaked by ANY means, then their entire private message history is viewable by whoever has the key, even for NIP-17 DMs, because even though they use NIP-44 encryption, there is not forward privacy.
That said, we're talking about DMs here. On literally any other social network, if someone can log into your account, they can see your DMs. The answer is to be careful with your private key and not use Nostr DMs for sensitive private messaging. There are better options for that.
@JeffG and team are building something promising with Whitenoise, which I believe is NIP-EE, but that kind of forward privacy isn't always desirable either, as it comes with tradeoffs when you use multiple devices/clients.
I am all for NIP-17 for standard DMs, especially when paired with auth, and NIP-EE when you want/need forward privacy.