Replies (43)

Kudzai Kutukwa's avatar
Kudzai Kutukwa 2 months ago
"Using on-chain addresses for zaps is a terrible idea precisely because it reveals more than necessary. And to add insult to injury, it automatically makes this oversharing permanent." That is all. View quoted note β†’
I already make an effort to not link my real identity to my npub, so the last thing I personally need is a public account of which Coin ATMs I've visited and when πŸ˜…
Yes! I agree. Great article. I will re-quote. Gigi, have you written/will you about moneros, please? Moving on to the future, I guess some things should be taken into account: - definitions that allow mist-use/bad practices will be mistused (the remediation would be redefining npub so that it becomes very decoupled - this might break backward compatibility or require some step for backward/forware migration)
I think a main issue was opposing concepts: - npub for building reputation - privacy or npub --- There is now reputation with a spectrum of knowledge about how much moneys are in the npub... Generating new npubs would be terrible.
synking's avatar
synking 2 months ago
Wake up babe, Gigi dropped a New piece.
No, I can decouple the whole thing. Data has to be shared if one wants to share and only with those one wants to share. We vsn define this with concentric circles. Problem is today when we say WOT its not web of trust... Its who one follows... Trust and reputation are defined nowhere... That's what I want to tackle with this... But I am struggling yo either get funds for that or sell some consulting project or sell more VPN subscriptions... I must go back to the deep dive and write the Architecture and implement some functionalities.
πŸ™‹ I am also a Londoner. In Hampshire right now but with goes in London for Luma tech/entrepreneur events.
Great article. One thing that wasn't really touched on, although maybe tangentially, is the idea that you could have no idea that you received any on-chain Zap at all. Only two clients support this misguided feature. That means that for all other Nostr users that are using other clients, they could have no idea that they've received on-chain Zaps to their npub. Since most clients (thankfully) don't support on-chain Zaps, their clients have no way of notifying them that they're receiving money to their npub this way. Furthermore, people who are using on-chain Zap clients (Ditto, Amethyst), these clients can't in any way determine if the person they're sending on-chain Zaps to use or have ever used one of these clients. It is far more likely than not that they'll be sending Zaps to a person who won't be notified in any way that they received anything. Putting aside all the horrible practices that on-chain Zaps have for privacy that you outlined, the entire argument for on-chain Zaps at the moment is convenience. But I can't think of a worse UX for a common user than to have build a payment system that will in all likelyihood result in the recipient not being notified that they received anything at all or not having any means for the sender to know who they can actually successfully send money to and who they can't. At least if I try to send a lightning Zap to someone without a LN address, it will say that I can't. That's what proper UX should do.
The cause for concern on this issue/problem with on-chain zaps that Gigi lays out here is crystal clear to me in his writeup. Sharing my thought stream here, internal dialogue of you will: Made me think if Alex and Vitor didnt do this, would someone else have? Someone else surely would have because it’s possible to do on nostr, and if something is possible, eventually, someone will do it. Apparently this is impossible to stop/mitigate at the protocol level in its current state. So at best, I think from a naive perspective, it’s the clients that can do something about this being acceptable behavior. But even then, anybody could create a fringe client using nostr and just do it anyway. This is a privacy design hole with the protocol. Maybe if nostr keys were derived using formats not compatible with bitcoin? Now I’m venturing into places where my foundation is very shaky so I think I’ll stop here. This is fucked up. View quoted note β†’
This analysis is bang on target. On-chain zaps are just the latest example of our (actually the devs’) willingness to sacrifice privacy for the sake of convenience. Primum non nocere is absolutely right. Keep fighting the good fight, Gigi!
fade2's avatar
fade2 2 months ago
This shouldn't even be a discussion. You all are getting baited. Move on.
Richard's avatar
Richard 2 months ago
It will repeat 2 years later for BTC
sumsur's avatar
sumsur 2 months ago
I forgot about the time I won the lottery
Just did, but be warned that all my footnotes and other stuff I have in there, while being valid markdown, usually breaks most long-form clients.
Maybe instead of footnotes, if they are links to other pages, link them directly within the text in the longform post.
Not gonna spend time doing workarounds. Clients need to fix their markdown rendering.
↑