Nostr DMs are end-to-end encrypted.

Reply to this note

Please Login to reply.

Discussion

Yes, just careful with social graph leak

amazed that isn't fixed yet #[5]

DMs haven't been a huge priority, but it will be fixed soon enough

Public features priority makes sense

Metadata is public.

Don’t treat DMs as particularly secure, they’re pretty simple an don’t have many of the good properties that existing E2EE messaging alternatives like Telegram/Signal/WhatsApp have (ratcheting keys, key exchange between two parties, etc.)

You leak your nsec and all your past DMs are readable and you’re easily impersonated. Also everyone can just see who you’re messaging and when, even if they can’t read it (because the DMs are jus events published to your relays like normal posts)

All true (: