Don't get me wrong, the nostr is great, but we really need to work on the privacy aspect of it.

We are creating so much data our message meta data, mutes, blocks, bookmarks and everything is wide open, even our IP is exposed to every relay we are connected to.

I understand that we can use VPNs for some privacy, but privacy should be built-in by design.

Reply to this note

Please Login to reply.

Discussion

Maybe clients should build proxies in or something

If the client can’t have the proxy because of bandwidth, maybe at least an option a part of onboarding:

Option 1:

You should definitely buy a vpn service before using Nostr

Option 2:

Pay us 20k sats a month to proxy your Nostr events

I'm concerned about privacy, so I hear you. However, I'd argue that whereas nostr has bloomed from a very simple protocol, others like DID, etc. have withered because they attempt to solve everything at the protocol layer.

We'll get there, in time, in layers.

I agree that protocol, like nostr is successful because it focus on solving a specific issue rather than trying to do everything at the protocol level.

Layers works btc perfect example but those privacy focused layers should become standard

I agree! It’s still early tho, but we need to work on that :)

Yes, but these things should/can be solved on an upper layers; like bitcoin.

We’re still at the equivalent of using p2pk.

You gave a perfect example, making upcoming privacy focused layers standard should be our priority.

Thank you for bringing this u πŸ€

This is at the root of Nostr, however.

An open and public network that enables things like social media where you own your data means that *each person* has to take personal responsibility to preserve privacy where they want it.

The easiest ways will be only using relays you trust/control and using a always-on VPN on all devices to hide true source IP.

Outside of that, people should assume everything in Nostr is public and act accordingly.

That is totally fine and should be a similar expectation as centralized social media, except that in this case *anyone* on your relay(s) can see all of that data, where as with Twitter etc. only Twitter and 3rd-parties they share with can.

If you make much of the data we're putting into Nostr private by default, it will be a pretty poor social tool.

Wow, You answered it perfectly.

"Nostr's open network and ownership of personal data require individual responsibility for privacy. Trustworthy relays and always-on VPNs are recommended"

I think it would be beneficial to address concerns around message metadata, private bookmarks, blocking and private spaces for users through the use of privacy focused layers.

Please continue to share how users can protect their privacy as much as possible here & everywhere else.

A simple step to take is to try out clients with local follow lists, like Gossip.

Another idea is to send LN tips instead of zaps: #[0]