19 ms·
Twitter's new encrypted DMs aren't better than the old ones
- deleted 1y ago[deleted]
- koakuma-chan 1y ago[flagged]
- brookst 1y ago[flagged]
- deleted 1y ago[deleted]
- deleted 1y ago[deleted]
- pilif 1y agoIt didn’t have a back door. A third party client was used whose only purpose was to log conversations. That third party client’s archive was then hacked. Any client must by definition have access to the unencrypted data (in order to display it to the user). If you deliberately create a client that logs all communication, well, then all communication will be logged.
- mschuster91 1y agoThat was a modified client you're referring to.
- treebeard901 1y agoWith all the ways devices leak data, even now with all the AI integration and the screen recording happening in Windows, it is safe to assume encrypted messaging is not as secure as it used to be. Onscreen keyboards and device notification systems also offer other areas that can leak what you type. The financial and legal consequences for companies that refuse backdoors are just too great.
- 77pt77 1y ago> even now with all the AI integration and the screen recording happening in Windows What! > Onscreen keyboards and device notification systems also offer other areas that can leak what you type. The keyboard one is really pervasive.
- two_handfuls 1y agoThe google keyword for the screen recording is: "Microsoft Recall". In summary: yes it's true. But only for PC equipped with some niche hardware (and Windows 11). Also, Microsoft promises these data don't leave your machine. Overall consensus is that this is a terrible idea.
- 77pt77 1y ago> Microsoft promises these data don't leave your machine I guess all is good then!
- ibotty 1y agoFWIW signal opts-out of recall. There is a blog post about it.
- prophesi 1y agoI'm assuming this is about TeleMessage https://www.404media.co/the-signal-clone-the-trump-admin-uses-was-hacked/ https://www.404media.co/the-signal-clone-the-trump-admin-use...
- nalekberov 1y ago[flagged]
- kstrauser 1y agoThat’s not true. Skepticism is good and welcome. Random allegations like “it has a backdoor” are not. If someone has demonstrable evidence that Signal is compromised, I’d delete it immediately. Until then it’s just unwarranted speculation, seemingly intended to make people “both sides” it and switch to something more popular and less secure.
- nalekberov 1y agoHere you go: https://consumerrights.wiki/Signal_Data_Collection https://consumerrights.wiki/Signal_Data_Collection I would never, ever trust anything that asks me to login using my phone number - which by nature is identifier. They have their own motivation to require phone number - but I will never buy this kind of things. That said, being open source doesn't mean it's private - at the very least they can collect enough metadata tied to my phone number. If my messages are sent via centralized servers owned by someone other than me who already have my identifier, there is no reason I have to trust them. Saying something against Signal always hurts some people's feelings, as if Signal is sacred object. There, I said it. You are free to downvote me. But that won't change the fact that they have collected data, just like WhatsApp et al.
- kstrauser 1y agoI’m not saying that article is wrong. I’m not going to read through that wall of text and vet every unlikely claim. I am saying it could hardly be more opinionated, directly calling the Signal team liars. Even the site’s own header throws a large grain of salt at it.
- prophesi 1y agoI unfortunately did read it. All of the claims are disputed, and everything with actual citations refutes them.
- Imustaskforhelp 1y agoSignal doesnt have a backdoor. You might be misguided By the media. Signal is one of the best software and foundations to exist. Period.
- thrance 1y agoNo. https://github.com/signalapp/Signal-Android/issues?q=is%3Aissue%20backdoor https://github.com/signalapp/Signal-Android/issues?q=is%3Ais...
- diggan 1y ago> All new XChat is rolling out with encryption [...] This is built on Rust with (Bitcoin style) encryption What does "Bitcoin style encryption" mean? Isn't Bitcoin mostly relying on cryptographic signatures rather than "encryption" as we commonly know it?
- 77pt77 1y agoIt's just a buzzword meant to add perceived value.
- nicce 1y agoFor me it feels like that after sending messages over 5 years, you need 1TB storage just for the Twitter app.
- thewarpaint 1y agoThe source of that comment is provably not someone with deep technical expertise so take that with a grain of salt.
- londons_explore 1y agoe2e encryption is easy if everyone knows public keys for everyone else. This is how GPG works for example. However, the challenge is distributing those keys in a trustworthy way - because if someone can tamper with the keys during distribution, they can MITM any connection. I assume this "bitcoin style" encryption is a blockchain or blocktree of every users public key now and throughout history. Ship the tree root hash inside the client app, and then every user can verify that their own entry in the tree is correct, and any user can use the same verified tree to fetch a private key for any other user.
- kstrauser 1y agoI’m not sure you appreciate how large that data structure would be if you had to ship it inside the app.
- 1y ago
- 1oooqooq 1y agowhy people keep giving it the good press connotation by calling it by the old name?
- jasonlotito 1y agoIt's not a good press connotation. Quite the opposite. As for why? The answer is in the article. > [1] I'll respect their name change once Elon respects his daughter
- owebmaster 1y agoThat is an interesting concept as it seems that Elon Musk's main battle is against people's right to not be called by an old name. Xitter transition have not been very successful.
- jeffhuys 1y agoIt's still running fine for me with actual interesting content. I don't get this take, feels like only people who don't use it at all (anymore) say it's been a bad transition or "X sucks now" but they're not using it. It's still just Twitter, but you're not being banned anymore. So ACTUAL discussions can take place without having the thought police running around with a banhammer.
- paulryanrogers 1y ago"ACTUAL discussions" like what? Because it would seem hate speech has had quite a surge: https://journals.plos.org/plosone/article?id=10.1371/journal.pone.0313293# https://journals.plos.org/plosone/article?id=10.1371/journal...
- righthand 1y agoThat’s a pretty damning study, post-purchase hate speech is nearly half the Twitter content. Sounds like hate speech is the “actual discussions”.
- maeln 1y ago[flagged]
- rschiavone 1y agoAlso openly endorsing a Nazi party like the German AfD [1], and if I had to link every single Musk's tweet where he says or endorses something homophobic, transphobic, racist, sexist or antisemitic I'd hit my character limit. [1] https://www.theguardian.com/world/2025/feb/24/elon-musk-congratulates-afd-alice-weidel-germany-election https://www.theguardian.com/world/2025/feb/24/elon-musk-cong...
- righthand 1y agoYes people forget but Elon was defending white supremacists on Twitter well before he owned the company.
- stavros 1y agoI read the first sentence and thought "that take sounds rather warm", but then I realized you were talking about Elon. Yeah, you don't get to casually throw a Sieg Heil at a public event and not get called a nazi, I have to agree.
- paxys 1y agoAnd someone who is (or at least until recently was) a part of the US government, with overreaching authority. Yeah, these are the people I trust to keep my communication private...
- rlt 1y ago[flagged]
- teddyX 1y agoSo you are saying that it’s not possible for someone who grew up around slavery and benefiting for apartheid to have racist ideology?
- owebmaster 1y agoIt is probably better for Xitter/Elon's plans.
- romaaeterna 1y agoGiven that Signal is pushing new code updates all the time, isn't it trivial for them to push new binaries that harvest messages/keys/whatever-they-want?
- yifanl 1y agoSure. If you don't trust Signal to not do that, then you likely aren't using Signal.
- JustFinishedBSG 1y agoYes but an app that never pushes update can also do that
- thrance 1y agoSignal is open-source [1]. You can compile the code yourself and review each PR if you're that paranoid. [1] https://github.com/signalapp/Signal-Android https://github.com/signalapp/Signal-Android
- Pesthuf 1y agoLooks like the build is even reproducible. That makes me trust Signal even more. https://github.com/signalapp/Signal-Android/blob/main/reproducible-builds/README.md https://github.com/signalapp/Signal-Android/blob/main/reprod...
- paxys 1y agoTheir client is open source and is routinely audited. Their Android builds are fully reproducible. You can also build and run the app yourself if you want instead of downloading it from the app stores. It is virtually impossible for them to ship a backdoor, at least on Android, without the security community noticing.
- romaaeterna 1y agoWhat exactly prevents them from doing a Windows build with an non-published change, signing it with the keys they control, and pushing it to an individual client through the upgrade servers which they control?
- paulvnickerson 1y ago[flagged]
- deleted 1y ago[deleted]
- linotype 1y ago[flagged]
- deleted 1y ago[deleted]
- yndoendo 1y agoWould the real XChat be able to sue X-Twitter for name infringement? http://xchat.org/ http://xchat.org/
- nadermx 1y agoMaybe? XChat would have to show an established market in commerce in each market that x is infringing that they have an established commercial precense in. Also it's harder if xchat doesn't have a trademark in each of those regions.
- remram 1y agoNo, they would have to show an established market in commerce in ONE market that X is infringing.
- deleted 1y ago[deleted]
- deleted 1y ago[deleted]
- pityJuke 1y agoMan, I remember being an IRC regular during the transition from XChat to HexChat. Now I learn HexChat is also dead :( [0] [0]: https://hexchat.github.io/news/2.16.2.html https://hexchat.github.io/news/2.16.2.html
- ChrisArchitect 1y agoEarlier discussion: X's new "encrypted" XChat feature doesn't seem to be any more secure https://news.ycombinator.com/item?id=44178008 https://news.ycombinator.com/item?id=44178008
- deleted 1y ago[deleted]
- consumer451 1y agoThanks. The top comment there gets pretty technical and ends with: > ... As noted in the help doc, this isn't forward secure, so the moment they have the key they can decrypt everything. This is so far from being a meaningful e2ee platform it's ridiculous. https://news.ycombinator.com/item?id=44178544 https://news.ycombinator.com/item?id=44178544
- michaelg7x 1y agoUsername matches the current URL
- jeroenhd 1y agoThe top comment is written by the person who wrote the blog post this thread is discussing.
- consumer451 1y agoAh, thanks. I try not to be guilty of just comment surfing, but this was not one of those times. :/
- b0a04gl 1y agoif this's using ephemeral keys with no forward secrecy and no ledger of interactions, what part of it’s actually bitcoin style besides the name?
- shiandow 1y agoBitcoin isn't a secure communication channel either?
- hoppp 1y agoIts all out in the public....
- masklinn 1y agoHaving no actual use?
- jeroenhd 1y agoBitcoin is great for prospecting, laundering money across borders, and scamming gullible people. It's also easier to hide a stash of stolen bitcoins from the authorities for after you get released from jail than it is to hide a stash of actual money. Bitcoin is certainly no alternative to actual money but it's not entirely useless. I think these Twitter DMs only does the scamming the gullible part, as you need to pay to use the feature and this is scamming people into thinking they're paying for secure messaging.
- lenerdenator 1y ago[flagged]
- deleted 1y ago[deleted]
- shiandow 1y ago[flagged]
- deleted 1y ago[deleted]
- upofadown 1y ago>...you're still relying on the Twitter server to give you the public key of the other party and there's no out of band mechanism to do that or verify the authenticity of that public key at present. ... >Signal doesn't have these shortcomings. Use Signal. Dunno that Signal is a really good counterexample for this particular aspect of E2EE messaging. The option exists to compare a 60 digit decimal number but the usability of this feature is such that most users don't even know that this is something they have to do. Just having a feature is not valuable if no one knows that feature exists and have no idea what any of it means. I like the approach used by Briar Messenger. They just have the user use the number that represents identity in the system. There is no misleading feature that maps a phone number to the actual cryptographic identity. This makes it much harder for the user to unknowingly use the system in an unsafe way. A Briar identity looks like this: briar://bafybeiczsscdsbs7ffqz55asqdf3smv6klcw3gofszvwlyarci
- deleted 1y ago[deleted]
- baby 1y agoAt this point i don't care if it's encrypted, just make it better.
- deleted 1y ago[deleted]
- dehrmann 1y agoI don't get most of the hype around end-to-end encrypted messages when the app's source code isn't available for audit.
- pityJuke 1y agoI do find it funny that the library Twitter is using (according to TFA anyway) self-describes itself as: > Caution > Experimental library! and > While this library is just a wrapper around the well known Libsodium library it still comes with high potential of introducing new attack surfaces, bugs and other issues and you shouldn't use it in production until it has been reviewed by community. [0]: https://github.com/ionspin/kotlin-multiplatform-libsodium https://github.com/ionspin/kotlin-multiplatform-libsodium
- deleted 1y ago[deleted]
- lifeinthevoid 1y agoMove fast and break encryption.
- ETH_start 1y ago[flagged]
- bilekas 1y agoUmm what ? Are you saying that we need to call Twitter X? And if not, we should get flagged? If that's the case I'd like to say it will always be Twitter for me.
- ETH_start 1y agoPeople should call it by its name. Using an old name that no longer describes it is confusing.
- toomanyrichies 1y agoAre you actually saying there are people out there who will be confused what the name "Twitter" refers to, but will know what "X" refers to? Are you able to keep a straight face when you say that?
- ETH_start 1y agoThere will be people who think that the platform is called Twitter and it's going to cause chronological mistakes where they refer to that term and then people think they're talking about the Twitter that existed before Elon Musk took it over. There will be others who think X and Twitter are different platforms. Using the wrong term is undoubtedly going to cause confusion.
- deleted 1y ago[deleted]
- pier25 1y agoThe Twitter brand is so strong it survives even after a rebrand.
- tptacek 1y agoI like everything Matthew Garrett writes but I can't resist being annoying about this: Signal has had forward secrecy forever, right? The modern practice of secure messaging was established by OTR (Borisov and Goldberg), which practically introduced the notions of "perfect forward secrecy" and repudiability (as opposed to non-repudiability) in the messaging security model. Signal was an evolution both of those ideas and of the engineering realization of those ideas (better cryptography, better code, better packaging). What's so galling about this state of affairs is that people are launching new messaging systems that take us backwards, not just to "pre-Signal" levels, but to pre-modern levels; like, to 2001.
- nickpsecurity 1y agoLet's not forget three things from prior leaks: 1. Core Secrets said the FBI "compelled" companies to secretly backdoor their products. Another leak mentioned fines by FISA court that would kill a company. I dont know if you can be charged or not. 2. They paid the big companies tens of millions to $100+ million to backdoor their stuff. Historically, we know they can also pressure them about government contracts or export licenses. Between 1 and 2, it looks like a Pablo Escobar-like policy of "silver or lead." 3. In the Lavabit trial, the defendant said giving them the keys would destroy the business since the market would know all their conversations were in FBI's hands. The FBI said they could hide it, basically lying given Lavabit's advertising, which would prevent damage to the business. IIRC, the judge went for that argument. That implies the FBI and some courts tell crypto-using companies to give them access but lie to their users. Just these three facts make me wonder how often crypto in big platforms is intentionally weak by governemnt demand or sloppy because they dont care. So, I consider all crypto use in a police state subverted at least for Five Eyes use. I'll change my mind once the Patriot Act, FISC, secret interpretations of law, etc are all revoked and violators get prosecuted.
- tptacek 1y agoThere is no such thing as "fines by FISA court". FISA doesn't hear adversarial cases and doesn't have statutory authority or even subject matter jurisdiction to enforce compliance on private actors. FISA is an authorizer for other government bodies, who then use ordinary Article III courts to enforce compliance. Other than the fact that they're staffed by Article III judges and not directly overseen by Article III courts, the FISA court functions like a magistrate court, not a normal court. So: I immediately distrust the source. People are going to come back and say "well yeah that's just what they tell you about FISA court, but I bet FISA courts fine people all the time", but no, it's deeper than that: private actors aren't parties to FISA cases. It's best to think of them as exclusively resolving conflicts between government bodies.
- zzo38computer 1y agoIt would be better to use separate software for encryption, and to get the public keys by meeting with them in place.
- LAC-Tech 1y agoQuestion: I plan to visit Peking soon, can I use Twitter there without a VPN? Thanks.
- dongcarl 1y agoSome roaming SIM cards aren't restricted by the Great Firewall, but in general, yes you'd need a VPN.
- cyberax 1y agoALL roaming SIMs aren't restricted unless the home telecom company cooperates. The roaming traffic passes over a global MPLS network to the home mobile network, so it's not restricted by the national firewalls.
- dongcarl 1y agoTIL!
- fewdaysto2025 1y ago[dead]