Flippin' bullcrap on this
Discussion
what about nip 101 and nostr:npub1tm99pgz2lth724jeld6gzz6zv48zy6xp4n9xu5uqrwvx9km54qaqkkxn72
? is this secure? the app is nice.
I hadn't seen that, I was thinking about a way to augment vitor's nip along the same lines. It's a good idea, but maybe could be improved by generalizing to a session key, which can represent one or more parties in a private chat (for scaling purposes) and which can be periodically invalidated or expire to limit the scope of key leakage.
Thank you for trying out our app. We are continually making improvements.
To be honest, our approach with nip101 is significantly different from Sealed Gift-Wrapped. While Sealed Gift-Wrapped hides metadata, we don't attempt to do so(metadata help the client subscribe to appropriate events). However, during private chats with friends, we use an alias pubkey to replace the real pubkey. This way, even if a third party obtains the metadata, they won't be able to tell who is chatting with whom.
And this is just the implementation approach of our app.