Its a compromise. You trust a nostr relay to keep something from others on your behalf. Best case, you only auth on your own server. That is pretty good privacy. Encryption is obviously the peak, but some things can't be encrypted: metadata, access logs, maybe private messages that can't be encrypted for some reason. That's the stuff you want auth for. To be fair, most nostriches treat a relay's ability to perform AUTH as a signal that it is trustworthy. We should probably use some other metric for trustworthiness and culturally make it popular.

Replies (2)

Yea, if it is your relay, there is no issue, but to understand the nuances of that an user needs a degree on nostr and stuff, and nobody really cares. Not even devs nor the nips kabbala