Someone posted an image of my encrypted nostr DMs on Twitter. Of course I know that it's possible to see the metadata but I didn't realize how creepy it feels. You can see who I talk to and when. You could deduce my social circles, maybe even real world activity related to my messaging patterns. From now on, I will stop using normal DMs on nostr. The traces they leave is horrifying and you shouldn't use DMs either. *Please do not send me any DMs from your npub if you have something to communicate to me.* Use a random npub or a giftwrap or use a different method or use a different network to reach me. Nostr DMs have always been a complete privacy hell and I urge anyone to realize this and act accordingly. I repeat: DO NOT DM ME. I WONT DM YOU.

Replies (85)

I saw Jameson Lopp take a dig at DMs on Mastodon the other day (which I already knew about). The message should be don’t use DMs for anything important on any social media platform. I’m new to Nostr so still learning how it works so thanks for pointing this out.
Yes, I wrote a note on this the last week, I'll repost it here: A piece of OpSec advice for #nostrplebs: #Nostr is fantastic and wonderful, but its resilience against censorship comes with inevitable trade-offs: Nostr is entirely public and open. Every single event you broadcast to the relays can be consumed by anyone in the world, and this doesn't just include the notes. For example, I can know with whom you've exchanged DMs and at what time (though the content of the messages remains encrypted). I'm not saying that #nostrices should hide who they are and what they think, quite the opposite! Just be cautious not to reveal personal information that could get you into trouble.
Merci beaucoup et ça m'étonnera toujours à chaque fois que j'entends, lis voit ce que l'être humain est capable de faire et me demande pour quel intérêt.. Dans la chaîne l'être humain peut être l'une des espèces la plus dangereuse du fait de sa propension à surfer avec ses aspects dantesques
Désolée que cela puisse vous arriver.. Toutes mes félicitations.. Merci d'avoir avec nous, cela me envie de retourner aux études. Bonne journée à tous n'oubliez surtout *ce qui ne va vous tue pas vous beaucoup plus fort *💜
Nostr has never promised privacy. I often try to push for more privacy in nostr, but it's often an unpopular opinion. "tracking" is pretty standard, I am told. It is, but there should be an alternative. NIP-04 goes a long way, but it would be even better if it was transpoted in a more private way, over HTTP or with privacy respecting sites or relays.
Clients could have a little warning when opening DM section about the reality of DMs. 🤔
I don't get why the Nostr community (clients & relays) has given up on supporting NIP-42. It'd prevent random users from doing this (but not the operators of the relays you use). Nevertheless feels like low hanging fruit. @semisol @fiatjaf you authored the NIP, any insights on this?
How often do you plan to burn accounts and start fresh? Is this the solution here. This plus no changing on nsec means horrible privacy and security. View quoted note →
Months ago a relatively large figure on nostr publicly said they were going to ask another user if they could reveal their identity in relation to a questioning post from a third party. They then proceeded to DM the public profile of the anonymous user using nostr DMs with public metadata. It was a relatively insignificant thing and the identity was shared publicly after so I didn’t raise this as a big deal, but it was still a fail from someone who should have been aware of the issue.
dawg, you realize you're just one "cyber pandemic" away from the metadata *and data* of your twitter dm's being public right?
Default avatar
nobody 2 years ago
Does oxchat fix this with private and secret dm?
Default avatar
deleted 2 years ago
Never should have beem created in the first place imo. Many great messaging options, like Simplex. Keep nostr simple imo
isn’t it ridiculous when anyone gets obsessed and stalks someone? a strange kind of mental weakness.
theweegit's avatar
theweegit 2 years ago
Why is it unpopular? Is it not possible? And if it is why aren't we given the option at least?
Default avatar
totte 2 years ago
Yeah no Meta Data gets people killed