Seen a lot of folks simping for Jack's new Buzz app and honestly disappointed. We've had better tools in #Budabit and #KeyChat for well over a year. And the "built on nostr" claim is really quite dangerous. Here's notes from a code audit of their repo I ran after test-driving: * Messaging is NOT E2E / not even NIP-17. Per Buzz's VISION doc: server-managed encryption (TLS in transit + at-rest) covers every channel, DM, and event *by design* — the server can read everything, to support enterprise eDiscovery/compliance. NIP-44 E2E is only a "future consideration" for DMs. Keypairs do identity/signing/audit, not confidentiality. Summary: email-gated access to AI features, nostr keypairs are used for internal audit trail. * Different trust model from NIP-17. Nostr wants the relay operator *unable* to read private content; Buzz wants the server *able* to. Same Nostr foundation, opposite privacy posture. This is a different customer than your normal nostr user. * Agent identity: each agent = its own keypair + a second signature tying it to its human owner + hash-chain audit trail; wired via the Agent Client Protocol (Claude Code, Codex, Goose). #KeyChat already landed on the same pattern: an agent is its own keypair plus a human owner who approves/vouches for it. This is a converged pattern rather than inventing anything new. Bottom line: If you have a business that needs to do fiat reporting on AI compliance, Buzz could be useful. If you are the average nostr user who is concerned about sovereignty and privacy you should only use Buzz with a separate keypair. Or go fork it and make it more nostr friendly!
Mynymbox - Privacy friendly hosting solutions's avatar Mynymbox - Privacy friendly hosting solutions
Is Buzz something we can use as community chat?
View quoted note →

Replies (4)