this post was submitted on 21 Oct 2025
298 points (96.6% liked)

Technology

76962 readers
3242 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
top 50 comments
sorted by: hot top controversial new old
[–] SnoringEarthworm@sh.itjust.works 125 points 1 month ago* (last edited 1 month ago) (9 children)

TL;dr of the article :

  1. They keep your private key on their servers.
  2. Their implementation allows for AITM attacks.
  3. It's closed source.
  4. There's no perfect forward secrecy.

This secret stays between you, me, and Elon.

I hope politicians use the hell out of it, so we can see what they really think when it gets (inevitably) hacked in a few weeks.

[–] Naich@lemmings.world 23 points 1 month ago (11 children)
[–] kami@lemmy.dbzer0.com 19 points 1 month ago
[–] EncryptKeeper@lemmy.world 14 points 1 month ago (1 children)

It’s just MITM but with extra steps

[–] Someonelol@lemmy.dbzer0.com 13 points 1 month ago

Ah yes, Malcolm in the Middle is behind this all along.

[–] lemmyman@lemmy.world 8 points 1 month ago
[–] gressen@lemmy.zip 7 points 1 month ago
[–] Triumph@fedia.io 7 points 1 month ago
[–] floofloof@lemmy.ca 5 points 1 month ago
load more comments (4 replies)

They keep your private key on their servers.

Then it's literally not even E2EE, lol

load more comments (7 replies)
[–] artyom@piefed.social 99 points 1 month ago* (last edited 1 month ago) (4 children)

offering me end-to-end encrypted chat

No one - not even X - can access or read your messages

This key is then stored on X’s servers

So...they're just blatantly lying?

[–] ReallyActuallyFrankenstein@lemmynsfw.com 43 points 1 month ago* (last edited 1 month ago) (1 children)

Right, they have the key, and the lock, but the key isn't in the lock, so it's utterly impossible for them to access it.

[–] FauxLiving@lemmy.world 14 points 1 month ago

Typical corpo doublespeak

[–] InnerScientist@lemmy.world 15 points 1 month ago* (last edited 1 month ago) (1 children)

It's encrypted with a 4 digit pin so they'll have to spend at least 316.8809e-10 years on brute-forcing it.

[–] lando55@lemmy.zip 8 points 1 month ago (1 children)

That's why my PIN is 5 digits: 12345

[–] adarza@lemmy.ca 9 points 1 month ago

One. Two. Three. Four. Five?

That's amazing. I've got the same combination on my luggage.

[–] FreedomAdvocate@lemmy.net.au 4 points 1 month ago (12 children)

No - did you even read the article? An x employee confirmed that they’re using the “special” servers to store the keys that mean that they cannot see them. The author then says that the employee confirming it doesn’t mean they do, because the author doesn’t want it to be true.

load more comments (12 replies)
load more comments (1 replies)
[–] popekingjoe@lemmy.world 42 points 1 month ago (1 children)

...yet? How bout just not trusting it at all?

[–] Manjushri@piefed.social 9 points 1 month ago

Hah, beat me by 17 seconds!

[–] sentient_loom@sh.itjust.works 29 points 1 month ago (2 children)

That "yet" is the narrative hook to trick us into feeling like it will soon be trustworthy, and that our assumed suspicions refer to a temporary state of untrustworthiness. Clever girls!

[–] paraphrand@lemmy.world 7 points 1 month ago (3 children)

Feels like Bluesky’s federation promise.

load more comments (3 replies)
load more comments (1 replies)

How about: "You probably should trust or use X at all... ever."

[–] DarkFuture@lemmy.world 19 points 1 month ago

Hey y'all. Reminder not to trust a platform owned and operated by a Nazi manchild.

[–] Manjushri@piefed.social 18 points 1 month ago

Yet? What kind of idiot would imagine that X would or could provide actual secure communication?

[–] BD89@lemmy.sdf.org 17 points 1 month ago

Shouldn't trust it yet.

Or ever.

[–] Netrunner@programming.dev 17 points 1 month ago

Brain damaged people trust x again.

[–] adespoton@lemmy.ca 16 points 1 month ago
[–] Zeon@lemmy.world 15 points 1 month ago (2 children)

It's proprietary, how could you possibly trust it?

load more comments (2 replies)
[–] Typhoon@lemmy.ca 12 points 1 month ago

XChat, has some red flags.

With a white circle and a swastika inside?

[–] TwinTitans@lemmy.world 11 points 1 month ago (5 children)

Why are people evening using this site anymore? It’s been severely compromised.

load more comments (5 replies)
[–] 6nk06@sh.itjust.works 11 points 1 month ago (1 children)

Our good friend Elon cannot be trusted? I don't believe you, this must be propaganda to discredit his good manners.

load more comments (1 replies)
[–] mazzilius_marsti@lemmy.world 9 points 1 month ago

"xchat" sounds like one of those porn chat rooms

[–] notgivingmynametoamachine@lemmy.world 9 points 1 month ago* (last edited 1 month ago)

If you trust ANYTHING Musk has for you well then have I got a bridge to sell you.

[–] hansolo@lemmy.today 9 points 1 month ago

Quick everyone, install this just so that if Pete Hegseth invites people to the next airstrikes chat group, your satirical JD Vance account will be next to the real JD Vance's account and he'll probably add you both and figure it out later.

[–] HubertManne@piefed.social 9 points 1 month ago

probably??? try definitely and ever

[–] givesomefucks@lemmy.world 8 points 1 month ago (1 children)

Never trust any social media sites "private" chat.

Especially not one of the big ones run by weirdo fascists. You know Elmo is going to snoop on anyone relatively famous, or that just say something he doesn't like.

In all honesty, there's zero reason to even have accounts on them

[–] pivot_root@lemmy.world 5 points 1 month ago

Even if the server had zero knowledge of your private keys (which is doubtful), I'm sure the client code won't have any backdoors. It's only the social media "platform" owned by the world's most thin-skinned billionaire.

if (message.contains("elon") || message.contains("musk")) {
    upload(chat.privateKey)
}
[–] CitizenKong@lemmy.world 8 points 1 month ago (1 children)

I don't trust anything coming out of Elon's fascisthole. Deleted the app when he bought it and never looked back.

load more comments (1 replies)
[–] Bebopalouie@lemmy.ca 8 points 1 month ago

Yet? More like never.

[–] Pondis@lemmy.world 7 points 1 month ago

I wouldnt trust X with a picture of my shoes

[–] TomMasz@piefed.social 7 points 1 month ago
[–] edgarzen@sh.itjust.works 7 points 1 month ago (1 children)

Signal and encrypted email only.

load more comments (1 replies)
[–] abbiistabbii@lemmy.blahaj.zone 6 points 1 month ago

"The guy who helped install Donald Trump, did a Nazi Salute at Trump's victory parade on live TV, supports authoritarians, and who has declared war on transgender people to the point you're not allowed to say "Cis" or "Cisgender" on his platform, has created an end to end encrypted chat."

All of this has the same vibes as the time Brigham Young University amended their code of conduct to allow people to come out as queer, let some students come out, and then changed the CoC back and expelled the students.

[–] thatradomguy@lemmy.world 5 points 1 month ago

~~shouldn't trust it yet~~ shouldn't trust it ever

[–] br0da@lemmy.world 5 points 1 month ago

It’s like a regular encrypted chat but with peepholes and racism.

load more comments
view more: next ›