New npub sends to the receiver, contains an encrypted event that can be decrypted by the the sender and receiver only. The inside event contains the actual sender and comment. Noone from the outside can see this. Damus and Amethyst support these.
Discussion
Double encryption could be used for regular DMs as well. The only metadata being leaked is that the receiver received *something* from *someone*. Much more privacy than it has now.
This idea has been kicked around for months but what we really need to do is define a NIP and begin implementing in a client to avoid the need to manually handle
