{"type":"rich","version":"1.0","author_name":"mleku (npub125…mlek0)","author_url":"https://nostr.ae/npub125uw9znxawyrvrc4lraf2ertm5k652ve4t87f74v7s7scp2qk2qswmlek0","provider_name":"njump","provider_url":"https://nostr.ae","html":"a little thing i learned out of this nsec leak experience. because nostr DMs are store and forward, if you ever leak your nsec, everything you say in DMs becomes publicly accessible. for this reason, in my work on a new protocol project i have in mind, a re-engineering of nostr fixing all of the errors i see in it, DMs are synchronous only, the relay protocol includes a mechanism for using relays as a proxy, the relays are default paid and use a lightning node to support direct, onion routed payments from users to enable onion routing of their event publication, so one always hides one's network location from any place one's events are published.\n\nsynchronous DMs means it's never stored on a relay. only chat partners get your messages, and they only get it via onion paths your client sets up. there will be a simple notification event in teh protocol to ping another user that you want to chat, for the initial case, and it's just going to be how it is - you can't chat unless you are both online. otherwise you end up with this problem where your nsec leak makes your whole chat history visible.\n\nanother thing that is in my mind about this protocol is that it deliberately requires you to understand a basic level of cryptographic and network topology things in order to use it. the protocol is not intended to win userbase, it's intended to provide a secure basis for people to communicate publicly and securely communicate privately. the coldcard hack incident is a case in point - adoption inherently exposes users to risks involving trust so any competent replacement for nostr has to eliminate that by raising the bar of entry so that you already have decent opsec before you can even start participating on it.\n\nanother thing is relays - they will be default requiring payment to use. this is for two reasons:\n\n- default event publication works using onion routing. to not make a honeypot like Tor that is only fundable by sketchy orgs that are probably mostly spook fronts, the relays have to be self funding\n\n- a baseline of cost for using relays is inherently going to lower the amount of spam on the protocol because every message you publish on it requires you to spend a little money. no spammer or scammer using spam to reach their marks is going to be happy about paying to use the network.\n\nthe cost of freedom on the internet is higher than nostr promoters would have you believe. it's worth it, and it's not worth weakening security for the benefit of userbase. the network of bad actors in bitcoin and nostr are exemplary for understanding why the bar has to be raised, and why using the network has to cost."}
