I don't want to be rude but if you send me a DM that is not giftwrapped, I'm probably not going to answer. Please use a nostr client that supports giftwraps (Amethyst, 0xChat, ...) or use Matrix to reach me (contact in bio).

If you don't use giftwraps, everyone can see that you've messaged me. Some bored weirdo is going to look at our metadata and post it publicly as a display of their genius. It happened in the past. I wish I could prevent people from sending me DMs here in the first place.

Please be aware of this and don't use normal nostr DMs to improve your own privacy and the privacy of your peers.

Stay nutty 🫡

Reply to this note

Please Login to reply.

Discussion

Clients should just deprecate nip4 DMs, and default inbox relays should be a thing forbetterr onboarding

the thing is, you can't just deprecate it for dm's and use it for other things https://github.com/nostr-protocol/nips/pull/1248

Why can't we? People can do whatever they want, but DMs need to not have leaks, so its in the best interest of the clients to remove it from DMs at least. Everything else can follow.

I don’t understand on primal, I got some, even I never dm someone

Does Damus support "giftwrapping?" If so, where is it in the UI?

giftwraps are a fucked standard

worse is better I guess? they are not ideal but it works.

all it protects is from metadata leaks, I would rather have metadata leaking forward secrecy

Do you mean that gift wraps break forward secrecy?

they have none which is a bigger deal than metadata leaks

This is somewhat technical and might be tricky to wrap a noggin around.

to get metadata privacy with giftwraps you make a fairly large tradeoff: you have to give up filting at the protocol level. you have to accept unmarked envelopes from anywhere. this can easily be abused and spammed, you have to unwrap the note to see who its from which has computational costs. so you could in theory DoS someone with lots of giftwraps and theres no way around that.

I believe semisol is saying that he would rather not make this tradeoff and just focus on tech that gives forward secrecy if he had to make the choice (correct me if I'm wrong)

They aren't mutually exclusive though, there are things like semisol channels where you could have fairly good metadata hiding and forward secrecy, but its a 1-to-1 thing instead of from anyone.

that’s one half of my point, yes

my other point is a solution offering forward secrecy only is preferable to metadata privacy only

Gift wraps also lack plausible deniability

Noggin wrapped. Thanks Will

nostr:note13vy95fl9akgukyv4lrazzwr9vnp2ycy0d0nxzg2rjg8uafq9fk8qfz7dx2

Short answer is yes. The challenge is extremely limited resources.

Unfortunately now days nip04 is the only reliable way you can ensure a person is going to receive your dm in their nostr app... nip17 needs a bit of more adoption

will primal have giftwraps ??

Only Matrix manages to leak almost as much metadata as NIP04 DMs 😂

Can you tell who I'm chatting with? Post below 👇

I can't. Thank god I'm the only one you need to worry about 🙈

So you're just making unfounded claims, gotcha.

Also assume your nostr DMs to be public one day when one of the two parties’ nsec is compromised, due to lack of forward secrecy.

I have Amethyst, but I can't find the functionality for gift wraps or NIP-17. It always sends NIP-04 messages. I know Amethyst is supposed to have NIP-17. nostr:nprofile1qqsyvrp9u6p0mfur9dfdru3d853tx9mdjuhkphxuxgfwmryja7zsvhqpzamhxue69uhhv6t5daezumn0wd68yvfwvdhk6tcpz9mhxue69uhkummnw3ezuamfdejj7qgwwaehxw309ahx7uewd3hkctcscpyug

You need to set your inbox relays, the nip17 messages are the incognito icon on the messages. If that is on it means the messages are private (as long as both parties don't have compromised keys of course). Amethyst does a backwards compatibility thing where it combines nip04 and nip17 messages with the same participants, which makes it a little confusing for someone wanting to start out, but I think its a good compromise since a lot of people simply don't care.

Thank you

Click the little spy icon in the DM text box to use giftwraps. I just sent you a DM

Which #Matrix client are you using? And why Matrix over SimpleX?

I use Element. Simplex is way too clunky for me as a daily driver, too many missing features when I tried, notifications rarely work etc.

I'm trying to replace Telegram as the main chat for Bitcoin dev as much as I can. Matrix has a mature ecosystem and is used by many, can be self-hosted. It's great.

Yeah, SimpleX definitely has it's UX issues

Just support 0xChat.

That is the way to improve it.

a petition wouldn't really make it go faster. it's really a manpower issue. I'm busy with notedeck and daniel is working on push notifications, lists, etc.

Well, keep up the good work :) Things take their time, it would just be nice that's all. Looking forward to it

So, simply using 0xChat does the thing or do I need to do anything else?

nprofile1qyw8wumn8ghj7mn0wd68ytfsxyh8jcttd95x7mnwv5hxxmmdqyw8wumn8ghj7mn0wd68ytfsxgh8jcttd95x7mnwv5hxxmmdqy08wumn8ghj7mn0wd68ytfsxvhxgmmjv9nxzcm5dae8jtn0wfnsz9rhwden5te0wfjkccte9ejxzmt4wvhxjmcpremhxue69uhkummnw3ez6vpj9ejx7unpveskxar0wfujummjvuqzqgycd7urua6ajmgc3jjunhcseekkz0swkljhdzs0pvftxlx6cgdnrd80dp Yakihonne support both encryptions ways (legacy and giftwraps) you should check it out, mobile and web app

K100

NIP-17?

How do you tell if it is giftwrapped before viewing it?

I didn’t know this was a thing. Interesting points to consider.

Thoughts on SimpleX chat? I found Matrix a lot of work.

Simplex is a good telegram replacement. However, it is not comparable to the power of using nostr.

Whereas with SimpleX you either use their default server or have the effort to setup a specific server, with 0xChat you use any nostr server and exist hundreds to chose from.

Thank you for this response. I will lean into learning 0xChat

The more people using nostr and 0xChat, the better.

I need a tutorial… didn’t realize gift wrapping was a thing…

Thank you. I didn't know anything about the gift wrap NIP until you mentioned it.

calle I think you have the sexiest voice I've ever heard and I want to have your babies

oh shit I meant to send this as a DM how do I delete? 💀

🥀

what’s a gift wrap

It's called DM, not PM.