Interesting. Does this allow you to see their DM’s as well?

Reply to this note

Please Login to reply.

Discussion

Super interesting point 🤔

You can see who they’ve DM’d but cannot decrypt to see messages or their contents.

No, because they are encrypted and require the private key to decrypt.

i can see who you are dm'ing - not what

Is it possible to make this more private? It can be disturbing to know that everyone can see who I'm talking to in private, right?! 🤔

Are private relays a solution for that ? #nostr #DM

yes, good to keep it in mind hehehe

no idea bout private relay tbh

A new specification will have to be written to address all privacy concerns regarding DMs.

One thing you can do right now is to always send from a throwaway account when DM-ing someone. Then it's only visible that the other party is having a conversation with someone unknown.

The other party could themselves respond from a throwaway account, to a _second_ throwaway account of yours. That way only the first DM is trivially linked to the other party.

DM sender, recipient, timestamp and message size is all public. You can see for yourself and browse e.g. here: https://brb.io/n/list?kind=4

People see "encrypted" and think it means "private". Something something we kill people based on metadata. People are going to get burned on this.

Tempted to make a bot that publicly mentions who DMs whom for visibility 🤔

obviously not, you need the priv key for that

No you need their private key for that.

You can still see who they were DMing tho

Had to try it! Not fast but it works. Wonder if the lighting network could use for onion routing... I get the stupidest ideas 😅

This of course doesn't help your metadata. If your IRL identity and IP is never known... meh.

let me check lol

Storytime; Recently I saw a post where someone made a screenshot of their messages, but blurred out the sender. I just copied the npub and checked who they messaged with. You can even see the time. Wasnt hard to find out who was blurred out lol.

No, you would need their private key to decrypt DMs.