Replies (2)

I think you guys are talking past each other a bit. @Logen is not saying that NIP-44 leaks key data. His point is that if a user's private key is leaked by ANY means, then their entire private message history is viewable by whoever has the key, even for NIP-17 DMs, because even though they use NIP-44 encryption, there is not forward privacy. That said, we're talking about DMs here. On literally any other social network, if someone can log into your account, they can see your DMs. The answer is to be careful with your private key and not use Nostr DMs for sensitive private messaging. There are better options for that. @JeffG and team are building something promising with Whitenoise, which I believe is NIP-EE, but that kind of forward privacy isn't always desirable either, as it comes with tradeoffs when you use multiple devices/clients. I am all for NIP-17 for standard DMs, especially when paired with auth, and NIP-EE when you want/need forward privacy.