the leak to the public is because of relays not implementing auth
at minimum, they should implement auth to access DMs
if everyone's relay did this, that problem goes away
it's never a better solution to use obfuscation when you can instead simply not send out the signal
Login to reply
Replies (1)
Agree. With it's not just AUTH as defined in NIP-42. It's AUTH + a p-tag filter based on the logged in user. Virtually no relay does this.
But even if it does. The relay itself SHOULD NOT be able to track anyone else but the user that connected.