Nostr DMs are end-to-end encrypted.
Discussion
Metadata is public.
Don’t treat DMs as particularly secure, they’re pretty simple an don’t have many of the good properties that existing E2EE messaging alternatives like Telegram/Signal/WhatsApp have (ratcheting keys, key exchange between two parties, etc.)
You leak your nsec and all your past DMs are readable and you’re easily impersonated. Also everyone can just see who you’re messaging and when, even if they can’t read it (because the DMs are jus events published to your relays like normal posts)
All true (: