pull down to refresh

More and more people started using Nostr, but not many people talk about how to use it safely—Nostr is not the social media we used to use, not something you can DELETE and pretend nothing happened.
Nostr: A simple, open protocol that enables a truly censorship-resistant and global social network.
Nostr is indeed a good tool against censorship, but it also comes at a price if you don't know what you're doing, and I'm going to share some of the safety practices that I've learned to help you stay safe in this Wild West.

How to Create a Nostr Account

  1. Ideally, use Alby or Nos2x to load your keys instead of from any Nostr clients.
  2. Save the key somewhere safe, e.g. using offline password manager keepassxc, and always have a backup.
  3. Choose any clients you like and log in with Alby.
    For Desktop
    • Primal: fast - I use this as my main client.
    • Snort: clean UI but quite slow - I use it as a backup when [Prima is down or fails to load.
    • Iris: average speed and average UI.
    For Phone
    • iOS: you can use Damus or Nostur - I like to use Nostur, but I normally use it for reading mode only.
    • Android: you can use Amethyst.

How to Find Interesting People or Content

Due to no algorithm in Nostr, it can be quite empty on your homepage if you don't know how or where to find interesting things, but there is one good tool to check notes or any activities: https://nostr.band/
For example,
see all the current popular notes https://nostr.band/trending/posts
see all the current trending users https://nostr.band/trending/profiles
A good hack is once you find some interesting accounts, then you look at what they are following.

How to Receive Zaps

There are many LN addresses you can link to Nostr, and I tested with different ones before, sharing two of my favorites here:

LNtip bot

This one is what I used to use - a simple LN address that you can easily create as long as you have a telegram account:
Features
  • simple use
  • got notifications
  • private comments available
Downsides
  • custodial wallet
  • need to use telegram for it
  • not much privacy
Hacks
If you would like to be more private, you can use sms4sats to sign up for a fresh telegram and then create an LN address with it instead of using your personal account.

Npub.cash

Another one of my favorites is the new kid in town: Cashu address. I've been using it for about one month now, and it's good for those who are up for more privacy or just being adventurous:
Warning: it's new, don't be too reckless using too large funds with it.
Features
  • private by default
  • no sign-up
  • automatic Nostr DM notification
Downside
  • custodial wallet
  • needs to redeem the sats manually
Hacks
The way how I use it is once the accumulated zaps reach certain amounts, then I usually choose Lightning to redeem it, and it will overcharge you some fee at first - all you need to do is paste a Lightning Invoice, and then you claim the leftover with any cashu wallets, e.g.enuts. ( you can either redeem the sats over Cashu or Lightning. )
And anyone can have it, yours is <yournpub>@npub.cash, but if you want to have a human-readable address, you can get one with 5k sats; And you even have an extra payment page that you can link to your own social or sites.

How to Verify NIP-05

NIP-05 is how you can have the purple tick in Nostr, it means verified, and there are different ways to verify it.
If you own any site(s), you can link to your Nostr account.
Step 1. Create a JSON text file in your domain
{ "names": { "<username>": "<hex-public-key>" } }
You can use this tool to get the hex of your public key and one more tip: if you want to leave the user name blank, then use"_", the veirfy address would then simply be yourdomain.com instead of username@yourdomaindotcom
Step 2. Enable CORS - enable the 'GET' and 'head' ( important step! )
Then you can use this tool to check if it's set up well.
Step 3. Link the LN address to your Nostr
Put username@yourdomaindotcom or yourdomaindotcom into your Nostr setting, done.
I set this up before, but later I found out that it's actually better not to stand out so much in the crowd, especially in the Wild West.
If you don't have any site, you can link your SN LN address as NIP-5 verification in Nostr.
Simply go to SN settings—Nostr—NIP-5, put your Nostr public key into the public key section, then go back to Nostr and put your SN LN address into the NIP-5 area, done.
Or getting verified through a service.
And many others, but I don't see any point in using them; okay, you can get the purple tick and an address so others can easily search you instead of using the long string, but seriously, linking to your POW makes more sense than buying a verification.

Safety Practices

- Always use a VPN
Nostr uses relays to communicate between Nostr clients, which exposes your IP address, meaning the relay operator can easily access your locations, but using a VPN can solve this problem.
- Use an extension to log
Use Alby or Nos2x to log in, and avoid copying and pasting your private key into any sites.
- Follow and engage wisely
Anyone can log in with your public key and see what you follow and engage with. **Every like, comment, zap, and note is permanent and PUBLIC.
- Avoid using DMs
The messages are encrypted, but the metadata, who you talked to, when, or small details like who initiated the conversation, how enthusiastic you were in the conversations or unwanted spam, and what time range you were online to reply (which potentially tells the time zone, etc) can be viewed by ANYONE.
- Only use trusted relays
Your notes could be nuked, but I haven't paid too much attention to this; However, here is one handy backup tool for it: nostrsync.
- The Art of Sharing
It's basically the same practice for using any social media, but always think TWICE before posting anything, and avoid posting anything too personal because you CAN'T delete it in Nostr.
  • For photos
Better remove metadata before uploading, especially the location.
  • For articles
Avoid posting directly. Ideally, post the links controlled by you instead then you can always trash the link whenever you feel like it.
  • Delay sharing
Avoid sharing anything in real-time, such as your current location; for example, I usually share things after I leave the place.
  • Cross post from SN to Nostr
Crossposting is quite handy for creators, but do remember that you can't delete anything in Nostr. I don't use this crossposting myself, I rather share a link in Nostr and from links that I can control—not only can I edit my content anytime, but I also have the freedom to trash the links whenever I feel like it!
However, for those who would like to use it, go to settings, enable crosspost to Nostr, and done; also, it only shows up on platforms like habla.news instead of directly showing up in your feed.

Final Words

Don't be so serious about the number games like in other social media because most of them are incorrect, and there are many bots there - better care less about numbers and cheap likes, but how many people actually trust you and willing to vote with sats.
Also, there is no privacy online - using Nostr can be a good training on learning about what's public and private - freedom comes with responsibility and think twice before you share anything there.
Have fun Nostring! 💜
Nostr is not the social media we used to use, not something you can DELETE and pretend nothing happened.
This is exactly what you could do, pretend. Nothing on the internet is truly gone. Even SN, where deleted items truly are deleted (I've viewed and edited the source code myself - but don't take my word for it), external services can take snapshots of content.
Nothing is deleted.
reply
privacy protection rule number 1: knowing what to share in public 👀
reply
If you have to think twice, the answer is probably - "don't" :)
reply
Site: UPDATE record SET visible=false
Person: Yay! I deleted my bad post!
reply
Wait until they can decrypt all the traffic from the past until the present.
reply
I see many interesting hacks inside this guide.... The force is strong with this one.
reply
learning from doing is the way! and I realized that it's quite easy to pretend to be smart with talking, but to find out the tips and tricks, one usually needs to do many POWs behind.
reply
one usually needs to do many POWs behind.
indeed... now you understand how much pow I put in my guides.
reply
and the crazy part, no other guides out there to read before the @DarthCoin practical guide - I wonder how did you figure it all out yourself. 😂
reply
Thank you for the excellent content. I would just like to add the following.

How to Create a Nostr Account

  1. Choose any clients you like and log in with Alby.
    • For Desktop
      • nostrudel: Packed with features others lack.
reply
feel free to add more:) and oh I didn't know this tool.
reply
Great post, as always. Hopefully, it helps the American Tik Tok refugees.
reply
77 sats \ 1 reply \ @kepford 19 Mar
Another great piece @Natalia
reply
thanks 🤓
reply
For some people this is also relevant:
  • Always use a pseudonym on the Internet.
reply
33 sats \ 1 reply \ @ek 19 Mar
Ideally, use a common term as your pseudonym so it's hard to search for you. Like table, apple etc.
reply
or more like using common names, def not using table, apple. 😂
reply
agree, and the best pseudonym actually sounds like a real name, nothing too standout. 👀
reply
Great piece, and some very good reminders about privacy and the inability to delete content.
The first thing I saw when I hit Primal today is that they're putting together a directory of posters in different categories, which is something I think a lot of Nostr newbies (or just folks who have been there for a while but not found a lot of content to engage with) would benefit from.
reply
33 sats \ 4 replies \ @398ja 19 Mar
I think nostr.build automatically removes all metadata from the media files you upload.
reply
but still, better rely less on others or any third parties.
e.g. I disabled all location setting on my phone, and are there more security hacks? @ek or any handy tools to sort things out before sharing in the wild? @0xbitcoiner
reply
My trick is to not take pictures in the first place :) I rarely take photos, let alone share them! Hahaha. But I have done it before, and my trick is to open the image in Windows Paint and "Save As" to create a new image. The new image does not inherit the metadata from the old one.
reply
I like to capture beauties, but I usually share them when I left that place.
But I have done it before, and my trick is to open the image in Windows Paint and "Save As" to create a new image.
I see. 🤔
reply
Here's a few FOSS tools for cleaning image metadata (EXIF) that I've just very quickly researched (and haven't personally used) :
reply
21 sats \ 3 replies \ @Diego 19 Mar
Thanks for this. Great guide. I’ve bookmarked. If I created an npub on mobile say Damus. And wanted to access this account on desktop day primal, how would I do this? Would i need to type in the private key on desktop?
reply
you can import your nsec into Alby or Nos2x.
sharing some extra fun before posting this, I was trying to remove the unwanted hyperlinks in some areas 👀
yourdomain.com
One solution that I found is you can use dot here: yourdomaindotcom, and it works great.
yours is <yournpub>@npub.cash
I still can't figure this one out, maybe <yournpub>@ npub.cash...
cc @ek
reply
121 sats \ 1 reply \ @ek 19 Mar
You could use ``: username@yourdomain.com and <yournpub>@npub.cash
reply
but then it's like highlighting unimportant things, any other more subtle ways? 👀
reply
I think that we shouldn't all rush to set up NIP-05. NIP-05 either breaks pseudonymity or puts trust in a third party. If we want to avoid spam, we can filter notes with low PoW at both the relay and the client level.
reply
Wow this is great! Love the safety practices!
reply
Wow excellent natalia thanks for putting it together 🙏
reply
Regarding the always use VPN point: do you think that Apple’s new iCloud Private Relay can offer enough privacy for using webbased clients on Safari?
reply
I have done amethyst, but somehow it's not getting integrated here. If you have any suggestions for a newbie like me.
reply
what do you mean by not integrated? 🤔
reply
When I post here with crosspost open to nostr, I always get some error message.
reply
11 sats \ 5 replies \ @ek 19 Mar
oh, it's probably because crossposting requires a nostr signer extension which you don't have on mobile and our error message is bad.
reply
I still do not understand why many people still use a mobile for everything. A mobile device should be strictly to answer your mom or GF calls and pay with LN. That's it. All the rest can be done nicely on a desktop.
reply
💯 I like to do things in desktop.
reply
I agree I also don't like to use cellphone so much. I use mobile because I don't have desktop or laptop, nor I have so much finances to afford it upfront. For an okay okay desktop or laptop, I need to stack only around 1 million sats. Maybe in a month or two.
reply
Where can I get that signer extension?
reply
22 sats \ 0 replies \ @ek 19 Mar
I am not aware of any for mobile but here are some for desktop:
reply
cc @ek 👀
reply