Security Experts Slam X's New Encrypted Chat Over Key Storage Flaws
TripleG News
1h ago
X, formerly Twitter, has introduced XChat, a standalone messaging app featuring end-to-end encrypted direct messages and topic feed filters. Users set up encryption by creating a four-digit PIN, which protects their private keys stored on X's servers using a system called Juicebox. This sharding approach spreads key material across three servers, but experts highlight significant risks since X controls all of them.
Cryptography specialists, including those from Cryptography Engineering, criticize the lack of forward secrecy and reliance on long-term public keys without continuous updates like Signal's double-ratchet mechanism. Private keys on X's servers—potentially without robust Hardware Security Modules (HSMs)—could allow X to access and decrypt messages, either for internal reasons or under legal pressure. Timing analysis suggests software-based HSMs, making brute-force attacks on weak PINs feasible.
This matters as X positions itself against secure messengers like Signal and WhatsApp, which store keys on-device. Critics argue XChat sacrifices privacy for multi-device support, including web browsers, eroding user trust amid Elon Musk's mixed privacy track record. Discussions on privacy forums echo skepticism, warning that proprietary cryptography lacks auditability.
Looking ahead, X must prove HSM usage and key ceremony transparency to build confidence. Until then, experts advise against using XChat for sensitive communications, urging users to prioritize proven E2EE apps.
Stay Ahead of the Curve
Join 10,000+ tech enthusiasts
Weekly digest · Curated picks · No spam
Related Articles
Iranian Drone Strikes Cripple AWS Data Centers in Middle East Amid Escalating Conflict
Amazon Web Services confirmed that drone strikes damaged three data centers in the UAE and Bahrain, causing structural harm, power outages, and service disruptions. The attacks, linked to Iran's retaliation against US and Israeli strikes, expose critical vulnerabilities in global cloud infrastructure.
X Rolls Out Standalone Chat App Amid Rising Encryption and Privacy Doubts
X has launched a dedicated web-based chat app for direct messages, separating them from the main feed to rival apps like WhatsApp. Security experts urge caution over unproven encryption as the platform pushes its 'everything app' ambitions.
QQQ Plunges Below $600 as Iran Conflict and Surging Yields Hammer Tech Stocks
The Invesco QQQ Trust ETF dropped below the key $600 level amid escalating U.S.-Israel strikes on Iran and climbing bond yields. The Nasdaq fell 1.02%, with semiconductor giants like Micron, Samsung, and SK Hynix leading the sell-off.