Replies (43)
"Using on-chain addresses for zaps is a terrible idea precisely because it reveals more than necessary. And to add insult to injury, it automatically makes this oversharing permanent."
That is all.
View quoted note β
the younglings reporting for duty π«‘
ππ§‘ I always enjoy your writtings so much, TY! I like learning interesting new stuff and you always deliver more than what I can expect, the memes, the cultural references, the links, the questions... It's fucking rich!!

I have not read it all but I came here to say something. What about a corrupt key manager. I think this is also a break point. What if another key wallet provider with a close source make a BIG marketing propaganda and a lot of users get on a scam and we are no here to say careful, Icarus?
Was nice to read you. I must write it.
A thoughtful post as always
Curious to where the silent payments discussion goes!
View quoted note β
...And those who are ignorant of the past are not qualified to generalize about it!
I already make an effort to not link my real identity to my npub, so the last thing I personally need is a public account of which Coin ATMs I've visited and when π
π«
I'm glad it was useful! π«
π«‘
Yes! I agree. Great article. I will re-quote.
Gigi, have you written/will you about moneros, please?
Moving on to the future, I guess some things should be taken into account:
- definitions that allow mist-use/bad practices will be mistused (the remediation would be redefining npub so that it becomes very decoupled - this might break backward compatibility or require some step for backward/forware migration)
I think a main issue was opposing concepts:
- npub for building reputation
- privacy or npub
---
There is now reputation with a spectrum of knowledge about how much moneys are in the npub...
Generating new npubs would be terrible.
I must develop this idea of reputation on the bellow project, nost_pass maybe have npubs for reputation...

BrunoSlingshotVPN (npub1clβ¦qtgjy) on Nostr
Short Text Note
Wake up babe, Gigi dropped a New piece.
No, I can decouple the whole thing.
Data has to be shared if one wants to share and only with those one wants to share. We vsn define this with concentric circles.
Problem is today when we say WOT its not web of trust... Its who one follows...
Trust and reputation are defined nowhere... That's what I want to tackle with this... But I am struggling yo either get funds for that or sell some consulting project or sell more VPN subscriptions... I must go back to the deep dive and write the Architecture and implement some functionalities.
π I am also a Londoner. In Hampshire right now but with goes in London for Luma tech/entrepreneur events.
Going at it with Gigo online is straight-up seppuku.
Gigi π€£
π
Great article. One thing that wasn't really touched on, although maybe tangentially, is the idea that you could have no idea that you received any on-chain Zap at all. Only two clients support this misguided feature. That means that for all other Nostr users that are using other clients, they could have no idea that they've received on-chain Zaps to their npub.
Since most clients (thankfully) don't support on-chain Zaps, their clients have no way of notifying them that they're receiving money to their npub this way. Furthermore, people who are using on-chain Zap clients (Ditto, Amethyst), these clients can't in any way determine if the person they're sending on-chain Zaps to use or have ever used one of these clients. It is far more likely than not that they'll be sending Zaps to a person who won't be notified in any way that they received anything.
Putting aside all the horrible practices that on-chain Zaps have for privacy that you outlined, the entire argument for on-chain Zaps at the moment is convenience. But I can't think of a worse UX for a common user than to have build a payment system that will in all likelyihood result in the recipient not being notified that they received anything at all or not having any means for the sender to know who they can actually successfully send money to and who they can't.
At least if I try to send a lightning Zap to someone without a LN address, it will say that I can't. That's what proper UX should do.
Worth your time to read and understandβ¦ youβre not just doxxing yourself
View quoted note β
The cause for concern on this issue/problem with on-chain zaps that Gigi lays out here is crystal clear to me in his writeup.
Sharing my thought stream here, internal dialogue of you will:
Made me think if Alex and Vitor didnt do this, would someone else have? Someone else surely would have because itβs possible to do on nostr, and if something is possible, eventually, someone will do it. Apparently this is impossible to stop/mitigate at the protocol level in its current state. So at best, I think from a naive perspective, itβs the clients that can do something about this being acceptable behavior. But even then, anybody could create a fringe client using nostr and just do it anyway. This is a privacy design hole with the protocol. Maybe if nostr keys were derived using formats not compatible with bitcoin? Now Iβm venturing into places where my foundation is very shaky so I think Iβll stop here. This is fucked up.
View quoted note β
Engineering is responsibility!
Thanks for this one
@Gigi
View quoted note β
Thank you Gigi, very useful π«Ά
This analysis is bang on target. On-chain zaps are just the latest example of our (actually the devsβ) willingness to sacrifice privacy for the sake of convenience. Primum non nocere is absolutely right.
Keep fighting the good fight, Gigi!
Great article, thanks for sharing!
This shouldn't even be a discussion. You all are getting baited. Move on.
It will repeat 2 years later for BTC
I forgot about the time I won the lottery
Can you post this as a NIP-23 longform post please?
Just did, but be warned that all my footnotes and other stuff I have in there, while being valid markdown, usually breaks most long-form clients.
Maybe instead of footnotes, if they are links to other pages, link them directly within the text in the longform post.
Not gonna spend time doing workarounds. Clients need to fix their markdown rendering.
On-chain zaps explained in a single picture, and in a well-written article.
View quoted note β

Me trying to forget when bitcoin was $1
View quoted note β