As for participation privacy, users don't seem to accept the lack of in-built transport level protection. As long as relays can track on the IP level who reads which groups, they would have a good enough picture of who participates where. That's why we design future chat relays that would handle group broadcasts as high-traffic messaging clients that don't have any network connections with group members (not even indirect connections).

Replies (2)

and auth
water783's avatar water783
If a relay requires auth, then yes — it could sniff some information. As for the other points: – The welcome event is wrapped in a NIP-17 DM, so it’s not linked to the MLS group. – Group IDs can be rotated, even per message. – IPs can be hidden by using the Tor network. Also, some information can be obtained from the req, but auth is required to identify the sender.
View quoted note →