Very complicated but it's the only option for large (100+ppl) encrypted private groups. In theory, it requires two centralized services, which we don't have in Nostr. But I think @JeffG found a way around these restrictions. It would be great if it worked. I am still unsure what relays, the public and users can track from one another over time. But it will likely require a Tor-like IP hiding system to make sure relays can identify keys when the app is doing REQs with multiple filters.

Replies (3)

What do you mean by “the relays the public and users can track from one another”? Re: IPs, yes. Relays could triangulate to some degree but usually only for short periods because all the visible group ids change regularly. Tor and some trust in relays is inevitable.
To get rid of IP addresses, take a look at Reticulum Network. Unfortunately, it's not widely used, so we have to build it first. #reticulum #reticulumnetwork
Some relays are collecting and selling information about users, like their interests and so on. Its likely that they will want to collect any info at their disposal to associate accounts/keys/secrets and sell them to the highest bidder. Picture Chainanalysis, but on nostr. If that breaks the privacy of MLS, then there might not be a reason to do MLS at all.