Replies (22)

To break correlation as to whom is messaging whom, use ephemeral private+public keys for private conversation instances and optionally exchange the pubkeys via a series of intermediaries. --- To mitigate metadata about sizes of messages, add padding --- To mitigate frequency which may reveal time of activity of participants, automate regular message transmissions (empty padded, ignored), and limit how often real messages are sent to the same interval
i’d argue it’s a relatively simple solution for now until they integrate SimpleX into clients (or make it Nostr native even πŸ€”)
Not a complete fix, but nevertheless a good defense in depth measure: https://nips.be/42 Basically, an authentication scheme so that relays wouldn't serve DM notes to anyone unless they can cryptographically prove that they're the intended recipient.
↑