Oddbean new post about | logout
 great #nostr privacy awareness info from the #amethyst github page:

Privacy on Relays & nostr
Your internet protocol (IP) address is exposed to the relays you connect to. If you want to improve your privacy, consider utilizing a service that masks your IP address (e.g. a VPN) from trackers online.

The relay also learns which public keys you are requesting, meaning your public key will be tied to your IP address.

Relays have all your data in raw text. They know your IP, your name, your location (guessed from IP), your pub key, all your contacts, and other relays, and can read every action you do (post, like, boost, quote, report, etc) with the exception of Private Zaps and Private DMs.

DM Privacy
While the content of direct messages (DMs) is only visible to you and your DM counterparty, everyone can see when you and your counterparty DM each other.

Visibility & Permanence of Your Content on nostr
Information Visibility
Content that you share can be shared to other relays. Information that you share publicly is visible to anyone reading from relays that have your information. Your information may also be visible to nostr users who do not share relays with you.

Information Permanence
Information shared on nostr should be assumed permanent for privacy purposes. There is no way to guarantee edit or deletion of any content once posted.

#cybersecgirl #privacytechpro #amethyst #nostr

https://github.com/vitorpamplona/amethyst?tab=readme-ov-file#privacy-on-relays--nostr 
 The privacy aspect of Bitcoin and Nostr is a bummer. I really hate that it seems like privacy is an after thought.  
 https://blog.cloudflare.com/encrypted-client-hello/

can some kind of ECH setup fix the ip leak issue? 
 Well the free VPN are of no help. Many apps doesn’t work if you are using VPN. They want you to disable to proceed https://image.nostr.build/371e63f12f9f74ee67f1085f51a2e919453bdc44afd1c734a8e129d3552b8ec9.jpg  
 It is missing an important route of privacy leaks: automated media loading. 
As it is right now clients connect to arbitrary web hosts to load embedded media in posts or DMs. The owner of that server can again see your IP address but unlike with relays you do not control which servers you connect to when loading media. 

There has recently been a campaign @Ostrich McAwesome to link pubkeys to IP addresses by sending a DM with a customized tracking link which clients automatically open because it disguises as an embedded  picture.