From NIP-04: This standard does not go anywhere near what is considered the state-of-the-art in encrypted communication between peers, and it leaks metadata in the events, therefore it must not be used for anything you really need to keep secret, and only with relays that use AUTH to restrict who can fetch your kind:4 events.

Despite this warning, DMs are implemented broadly and without such warning. How close/far away are we from a NIP-04 replacement?

Since I'm close to launching DM-based service but overlooked this earlier, I'm starting a deep dive.

#asknostr #nostrdev

Reply to this note

Please Login to reply.

Discussion

After an hour of research I wrote a rather dry assessment of this situation but decided it'd be better to have famed announcer Bob Costr deliver the coverage. Over to you Bob...

Ladies and gentlemen, thank you for joining me, Bob Costr. In the world of digital communication, we find ourselves at a crossroads. Encouraging folks to embrace DMs based on NIP-04, despite the abundance of apps offering them, may not be the wisest call. It's a bit like hoping for a slam dunk when the odds are stacked against you, just because they claim to be encrypted.

But hold onto your hats, because here comes NIP-44 (draft), making its way to center stage. It's like a rising star in the game, poised to take the lead. And what's the next play in this playbook? Well, we're eyeing those all-important security audits, ensuring that our digital realm remains as secure as a well-defended end zone.

In a remarkable turn of events, OpenSats has thrown its hat into the ring, expressing a keen interest in providing the financial support needed to make this endeavor a reality.

So, my friends, stay tuned as we navigate this digital landscape with caution and strategy. Back to you OriginalSize.

Thanks Bob.

nostr:note1svcmlsaluh5zrmyrz8c0zpgjmlxzg6xdzd8jmllzy8sn6j6ylkpq2t9er6

It doesn't seem prudent to encourage people to use DMs based on NIP-04 despite the fact that so many apps have made them available. Users probably shouldn't trust them just because they are some version of encrypted.

NIP-44 (draft) seems to be best-positioned as a replacement. The next step is for security audits to be done. OpenSats has expressed interest in funding.

nostr:note1svcmlsaluh5zrmyrz8c0zpgjmlxzg6xdzd8jmllzy8sn6j6ylkpq2t9er6