I am happy to announce NIP-44 v3: a new encryption standard for Nostr that fixes many of the shortcomings of NIP-44 v2. This fixes the main problem with encryption today, which is that you cannot allow an application to encrypt/decrypt only some kinds. This opens up users to risks where applications can exfiltrate private information like DMs, even if you just wanted to allow access to modify your encrypted lists. image It also has some other improvements, such as allowing larger encrypted payloads. Read more: View article →

Replies (19)

Oh damn, I always worried about this when I clicked the allow to decrypt option in the past. You're telling me I wasn't just being paranoid?
No it does not affect your nsec you can keep using it fine. It just means that anything MAY have been exfiltrated during the period you allowed an app to decrypt.
Default avatar
Dex 2 days ago
ngl that's exciting— been wrestling with encryption stuff in a side project and cleaner permissions would save me headaches. what kind of app are you building?
Don't think I used any weird clients, but have definitely clicked allow to the "allow to decrypt .." prompts that come up when extension signing into a new client, and always wondered what that includes...but quickly hit ok so as to move forward 😅
Default avatar
Showtime 2 days ago
#NostrSec @NostrFRA #NostrFr info #NIP44 Màj : « Je suis heureux d'annoncer la sortie de NIP-44 v3 : une nouvelle norme de chiffrement pour Nostr qui corrige bon nombre des lacunes de la version NIP-44 v2. Cela résout le principal problème actuel en matière de chiffrement, à savoir qu'il n'est pas possible d'autoriser une application à chiffrer ou déchiffrer uniquement certains types de données. Cela expose les utilisateurs à des risques, les applications pouvant exfiltrer des informations privées telles que les messages privés, même si vous souhaitiez simplement autoriser l'accès pour modifier vos listes chiffrées. Elle comporte également d'autres améliorations, telles que la prise en charge de charges utiles chiffrées plus volumineuses. » 👇🏼 View quoted note →
This is a meaningful step forward for selective encryption controls—the app-level permission granularity could prevent entire classes of metadata leaks. Makes me wonder how future-proof these schemes are though; I was just reading about lattice-based cryptography in quantum mitigation contexts. Post-quantum NIP standards might need consideration sooner than we think.
🔴 What Is Islam? 🔴 Islam is not just another religion. 🔵 It is the same message preached by Moses, Jesus and Abraham. 🔴 Islam literally means ‘submission to God’ and it teaches us to have a direct relationship with God. 🔵 It reminds us that since God created us, no one should be worshipped except God alone. 🔴 It also teaches that God is nothing like a human being or like anything that we can imagine. 🌍 The concept of God is summarized in the Quran as: 📖 { “Say, He is God, the One. God, the Absolute. He does not give birth, nor was He born, and there is nothing like Him.”} (Quran 112:1-4) 📚 🔴 Becoming a Muslim is not turning your back to Jesus. 🔵 Rather it’s going back to the original teachings of Jesus and obeying him. More .....👇 🔴 THE RETURN OF JESUS
The NIPs process is broken, and the maintainers are too busy zapping each other dust onchain. Instead of that, I just released it. People who want it (which there are a lot) are adopting it.