Oddbean new post about | logout
 Nostr clients should rethink automatically rendering all images found in notes. Most users are not aware this leaks request info: IP address (thus location), device, browser.

https://whodis.fyi/data.png 
 Iris.to loads all images over a proxy, unless the domain is on a list that currently includes imgur.com and nostr.build. 
 That's great. Can you share what the image proxy service is? Other clients should consider using it.
 
 We did operated a proxy. But then I realized that I not only had all the locations for our users but ALSO all their image and content requests. And I could easily associate both. The proxy doesnt only knows your location but know what you are looking at in real time. 

To me, the proxy is WAY worse from a privacy standpoint.  
 You can use this to check what info your #nostr client leaks:

https://whodis.fyi/data.png

nostr:nevent1qqs84xhkzsxqskh77lnmv3u9cqa8079gt42d7dh3ed77pzy2uzwsj4qpzpmhxue69uhkummnw3ezumt0d5hsygzxpsj7dqha57pjk5k37gkn6g4nzakewtmqmnwryyhd3jfwlpgxtspsgqqqqqqs4lc7gj

From:
nostr:nevent1qqs8xwy0l4k47lh563es2l5rtzk9yhe3hd5jywceh8mt39f78ty8weqpzamhxue69uhhyetvv9ujumn0wd68ytnzv9hxgtczyzu0pauuz6yd3083duen5tzkz73v8y65d89m6nkw8xy9dvdr7lhwqqcyqqqqqqgt0pxx0 
 We have embed tor that reason. If people want they can protect themselves. 
 By the way I am also from Malta. 🥂 
 Oh the image changes based on your ip and location... I get it 
 I thought this 🟠 🐇 🕳️ was teaching me a lot about security. 

Then I started using this 🟣 and I realized I was only at the pre-game apparently. 😂

Thanks for sharing so we can all be more secure while 🏃 this 🟠🟣.