Oddbean new post about | logout
 Do you mean that gift wraps break forward secrecy? 
 they have none which is a bigger deal than metadata leaks 
 This is somewhat technical and might be tricky to wrap a noggin around.

to get metadata privacy with giftwraps you make a fairly large tradeoff: you have to give up filting at the protocol level. you have to accept unmarked envelopes from anywhere. this can easily be abused and spammed, you have to unwrap the note to see who its from which has computational costs. so you could in theory DoS someone with lots of giftwraps and theres no way around that.

I believe semisol is saying that he would rather not make this tradeoff and just focus on tech that gives forward secrecy if he had to make the choice (correct me if I'm wrong)

They aren't mutually exclusive though, there are things like semisol channels where you could have fairly good metadata hiding and forward secrecy, but its a 1-to-1 thing instead of from anyone. 
 that’s one half of my point, yes

my other point is a solution offering forward secrecy only is preferable to metadata privacy only 
 Gift wraps also lack plausible deniability 
 Noggin wrapped. Thanks Will