Someone posted an image of my encrypted nostr DMs on Twitter. Of course I know that it's possible to see the metadata but I didn't realize how creepy it feels. You can see who I talk to and when. You could deduce my social circles, maybe even real world activity related to my messaging patterns.
From now on, I will stop using normal DMs on nostr. The traces they leave is horrifying and you shouldn't use DMs either.
*Please do not send me any DMs from your npub if you have something to communicate to me.*
Use a random npub or a giftwrap or use a different method or use a different network to reach me.
Nostr DMs have always been a complete privacy hell and I urge anyone to realize this and act accordingly.
I repeat: DO NOT DM ME. I WONT DM YOU.
Login to reply
Replies (38)
The doctor has a point.
View quoted note →
Let's attach a @SimpleX Chat recommendation to this
Clients could have a little warning when opening DM section about the reality of DMs. 🤔
timing attacks can be fairly sophisticated
We should boost @SimpleX Chat imo.
🤔🤔
I don't get why the Nostr community (clients & relays) has given up on supporting NIP-42. It'd prevent random users from doing this (but not the operators of the relays you use). Nevertheless feels like low hanging fruit.
@semisol @fiatjaf you authored the NIP, any insights on this?

GitHub
nips/42.md at master · nostr-protocol/nips
Nostr Implementation Possibilities. Contribute to nostr-protocol/nips development by creating an account on GitHub.
If you used simplex couldnt someone also post a screenshot of that chat?
What is a giftwrap?
you need to be a party of that chat to do that. The nostr dm meta data is public for any third party to map and visualize / track.
Messages are encrypted, but reciever and timing is public in nostr dms.
At the same time i dont see a HUGE problem because.. they are DMs, not PMs.
Direct message, not private message.
Aight, then we got that sorted out :)
Fair point. The DMs might be a good place to share contact info to private messages, for instance. So I agree with you here.
DMs are just for sharing SimpleX links. 😅🤣
Based 🗿
Does oxchat fix this with private and secret dm?
Put simplex link in your profile 🫡
Never should have beem created in the first place imo. Many great messaging options, like Simplex. Keep nostr simple imo
The protocol is able to handle it simple, i think. But too simple got privacy threatening.
Yes but we're still small.
Interesting view. Does this change your mind, @calle?
In which sense based?
Hahahahahahahaha
Follwoing you right now. 🫂
See Amethysts for example. Can't explain technically at the moment. h/t @Vitor Pamplona
Pulsar is pretty cool, private messaging on Nostr. TOR is down, but it works on clear net. Star it on Github. 
GitHub
GitHub - supertestnet/pulsar: My submission for the HRF's encrypted group chat bounty
My submission for the HRF's encrypted group chat bounty - supertestnet/pulsar
It's a feature not a bug
Good to keep in mind!
btw:
View quoted note →

SimpleX Chat - Contact
I imagined a prompt reply with a SimpleX link on any message, no matter what xD
I'm in Amethyst right now, but still don't fully understand. I appreciate the effort of guiding me towards an example though :)
runs like shit for me, laggy and slow and buggy
Ask questions.
Don't trust, verify
View quoted note →
yep latest runs way worse for me
is your room still up?
cant join, new version sucks