I don't care about your long thesis on how nostr works, billions of people don't care either you are the developer, you are the brains! you need to make what I want, I will not accept any half solutions,
SondreB's avatar SondreB
Nostr became popular because of "dumb" relays, Nostr using centralized gate-keeping relays defeats the original ethos of Nostr, and just makes it a very bad protocol (due to all its issues) to use for such purposes. I fully understand the desire to have a Facebook-style locked down experience, the way to do that is not through filtering on who is allowed into a relay, but what a client decides to load. Nostria does client-side filtering for threads, there is no problem doing a filtered query that relies on your following, or following lists - which will give you partially what you're after, though doesn't stop anyone from seeing the posts and photos. I could implement a following list with a known "d" tag which is your approved Friends list - which you populate only from friend request DMs. I built a social network on decentralized web nodes (Web5) a couple of years ago and that relied on an incoming friend request event. I might just implement this in Nostria when I think of it. Nostr is not a privacy protocol, some people believe that. It's an extremely leaky protocol and there is nothing anyone can do about that. It's a decentralized and distributed protocol. X became popular because it reduced the jumps from you to anyone in the world, to 1. You could engage directly with anyone without needing to be "accepted" first. You could get response from people who you found interesting, people who you normally would never be able to get access to. I wrote a lot about this in a blog years ago. It is the primary difference between X and Facebook. This is also why Nostr became popular, developers could build code that published events without anyone needing to accept them first. Nostr would never be where it is today, without this. NIP-42 (Auth) came almost a year after the protocol was first announced by @npub180cv...h6w6. NIP-70 (Protected Events) just two years ago. NIP-70 is just a tiny little hack to reduce spreading events to the major relays, it doesn't add any real privacy or protection. Anyone with access to that relay can in a few minutes publish everything to the public. As as you mention, it's not really possible to do private on Nostr and if people want that, they should use something else. Implementing a new protocol based upon Nostr identities for this purpose, can be a very good idea and is fully possible to do. This can be solved on the client and that's the only place it should be solved. Attempting to solve this on relays is going down the wrong path, it's attempting to use bad tools to achieve a goal. Pure spam is a different topic and relays need to fight that, and it's a hard challenge. The person responsible for fighting spam on X has basically capitulated few days ago and said from now on we're all toast. Just as you can't stop anyone from talking about you in their own home, you shouldn't think about stopping someone from commenting on your posts, instead the mindset should change towards not retreiving those events to begin with. You can ask the relay to not get what others are saying about you, or to you. It's like avoiding going into your neighbor's house if you don't want to hear what they have to say about you. You can choose to not go there, but you can't stop them from talking about you in their own home (I don't consider each home to be a relay, but a relay is the neighbourhood or the world, we share the space, just as we share the space on a relay). Private group chats is the only way to do private on Nostr (until Marmot Protocol becomes more widely available and used). If people want to share photos of their family and kids, they can do that in a private group chat. What people post, they should consider public. The legal system (not that anyone should care about that) in many countries even considers private groups as public, talking bad about someone in a private Facebook group, can get you in legal trouble as it's considered public. These centralized apps reduced the consquences, at least before, to tedious data gathering done by humans (screenshots, copy-paste), on Nostr it's super fast due to the protocol to gather all the data. With AI tools, this data gathering from "private" groups is going to be even easier. Implementing a "Friends only" mode is a good idea (as long as it's not considered a "private mode"), the protocol does support it, but it requires to reason about the protocol in the right way, as I have explained above. Though of course, it does not stop anyone from seeing your posts (and media).
View quoted note →

Replies (5)

It's easy to make what you want, it won't be Nostr-native, but it will use Nostr identities (keys) for accounts. Spam-attacks (friends requests) can still happen, but can rely on Web of Trust to filter out, giving a similar experience as Facebook/X. For what purpose though? Why not use Facebook instead? Building this, won't be decentralized in architecture, as you "can't" have decentralized and private at the same time. Could build it on Nostria, but I doubt there are any market for this (people willing to pay or revenue through advertisement with few users is worth little) and I would just be providing yet another service for free. What are your thoughts on the financial nature of such a social network?
spam attacks won't happen, the web of trust is dumb, it doesn't work, i don't think you understand, I will explain to you again, there will be a button on everyone's profile that says "friend/follow" request, if I click on it, it opens an invoice and u need to pay 21 sats or less, the sats go to either the app developer or the profile getting the friend request, no bot farm will send mass friend requests because it's cost money. it's possible, you just need to think harder, you also need to stop the mindset of advertisements, advertisements is not the future,
You never explained it to begin with, so you didn't do it again. Thanks for clarifying. There will be plenty (spammers, stalkers, attackers, bots) who will send 21 sats for friend requests and the advertisements will be in the profile names and profile pictures. Also will be a lot of fakes, attempting to infiltrate friends lists. Many will succeed. Many will loose their private keys to scammers. Those people will "call the support center". Did you know that a large part of Facebooks ad revenue is from scammers? Mitigating these things costs a lot of money. Nobody is willing to pay the actual cost of the services they use. Everything is subsidized by VC money or ads. Exactly what you want has already been attempted, "Lotus" it was called. The only difference was that you could set the cost of your inbox ourself, which would be better than a fixed 21 sats. The concept is that if you are attractive for some reason and people want your attention, they will pay more. You can also make it 1 million sats, but you "pay it forward" or "pay it back", depending on the scheme. So your family already knows you, so they don't have a problem sending 1 million sats in a friend request to you, they know they will get it back. This exact concept has already been done in traditional social media apps, I don't believe it had any long term success.