Oddbean new post about | logout
 The nostrudel feed of who messaged whom is scary.

NIP4 was a bad idea... 

https://image.nostr.build/e626f22d0be1e42691d58d04736b94ffa0a7bfd0659613a031cfe3064a6c7c8b.jpg#m=image%2Fjpeg&dim=1080x1865&blurhash=%5D484b%3D%7EqD%25%25LjDkCNGs%3BWBM%7BayjcoNWBRjRjofoffikBt7ofj%40a%7BWUV%40axWARjoft8aya%7Bj%5DWBjIRPWAV%5BWB%25MRjxts%3AIU&x=755046e648fd284bcd386e9835e83234f1d1128ac00c36a9ec53f396f7362ff2

https://nostrudel.ninja/#/tools/dm-feed 
 Mostly me messaging my bot. 
 NIP-4 Security Warning - why i use simplex and not #nostr dms

This standard does not go anywhere near what is considered the state-of-the-art in encrypted communication between peers, and it leaks metadata in the events, therefore it must not be used for anything you really need to keep secret, and only with relays that use AUTH to restrict who can fetch your 'kind:4' events.

nostr:nevent1qqsp0raxywwh5vvgxf5ec8tjgz4a96ruxrdtkjwxvnae7k8nznwc3jspr3mhxue69uhkummnw3ezucnfw33k76twv4ezuum0vd5kzmqzyzm7669svt0xkjsju50a22zurc0qa589z2xd4yatzx6p2z64a5e0cqcyqqqqqqg2cycxe 
 The worst part is the telltale simping 😖 
 As the person whose metadata is most exposed along with nostr:nprofile1qqszzv6swdqp5vgveytelca806txvugvlhmrph7cgruh9svr5fztrtgpz4mhxue69uhhyetvv9ujuerpd46hxtnfduhsz9nhwden5te0v4jx2m3wdehhxarj9ekxzmny9uq3wamnwvaz7tm8d3hkyctv9eex2mrp0yh8yety9u8vev2m , I love this. Maybe not for everything though 😅 
 Creepy. 
 It would have been elementary to send a new npub with the encrypted payloads and make all those traces disappear. I proved this method works in my code on Indra written early this year. 
 NOOOO NOT AGAIN