pull down to refresh
106 sats \ 6 replies \ @didiplaywell 8 Sep \ on: Stacker Saloon
Hello! I have been playing around with Nostr apps for group chat. "NostrChat" is neat, but a thing I can not understand is the concern about privacy: it's permanently stated that group chat conversations are public, yet when I write something there, it isn't shown anywhere else (like via njump.me for example). So what I'm not understanding is: in what sense are group conversations "public"?
PD: I wrote a DM with yakihonne and was able to see the same conversation via NostrChat, what an absolutely orgasmic feeling, I'm insanely bullish on Nostr.
in what sense are group conversations "public"?
Anyone could fetch these messages from relays with the correct query. You don't see them in clients like njump.me because clients are specialized and only show a part of nostr. That doesn't mean that these messages are private.
reply
But, for example, the message I wrote in yakihonne was, in theory, encrypted by the NIP-04 protocol. What you imply is that anyone could still fetch the messages and decrypt them? My concern about privacy is that anyone could freely read the content of the messages, is that what you mean it's possible?
reply
reply
It has to be NIP-04 at least, I wrote the DM in yakihonne with NIP-04 selected (it lets you chose between either NIP-04 and NIP-44), and NostrChat picked it up, so the protocol must be compatible. We can go a very long way with all metadata being visible, the privacy of the content is the only thing that matters for all practical purposes in our case. So if that's confirmed, then it's already a fully working solution for me.
reply
I found this:
Step 3 — Create a new chat channel and share with Nostr friendsOnce you join NostrChat.io you can chat in the global channel or create a new channel for your project or friends. Just share the URL of the channel with your friends. IMPORTANT: These channels are all public. At this time, there isn’t a way to make private group chats.
I guess they mean that anyone can join the channel if they have the URL. There is no "invite only" mechanism that be configured by an admin or similar.
reply
Thank you for checking :)
I did saw that but was confused too about what the definition of "privacy" was.
I finished testing going back and forth with two accounts and the state of the art for NostrChat is:
- Messages do are encrypted for I need the nsec key to decrypt a message sent to me.
- Groups are public as you described: anyone with the link can get in, and there's no admin capabilities other than being able to change the group title, description, icon, or to delete it. So groups can be easily invaded and not only you can not expel a user, but you can not even mute him. You can only hide one comment at a time. So the only thing you can do with a ruined group is to delete it. This is a fundamental deal-breaker sadly.
A group chat client I saw that has a lot of potential is "0xChat", but it's not available for Android 9 :'(
reply