• artyom
    link
    fedilink
    English
    102
    edit-2
    1 month ago

    offering me end-to-end encrypted chat

    No one - not even X - can access or read your messages

    This key is then stored on X’s servers

    So…they’re just blatantly lying?

    • @FreedomAdvocate@lemmy.net.au
      link
      fedilink
      English
      41 month ago

      No - did you even read the article? An x employee confirmed that they’re using the “special” servers to store the keys that mean that they cannot see them. The author then says that the employee confirming it doesn’t mean they do, because the author doesn’t want it to be true.

      • Natanael
        link
        fedilink
        English
        1
        edit-2
        1 month ago

        There are hardware for that called hardware security modules, but yeah I definitely wouldn’t trust Twitter’s implementation - especially because they probably just need the auth team to tell the HSM that the user logged in when they didn’t to get that key

        A proper implementation would use multiple security measures and require a reset (delete) of certain private account data before the account access can be reset, otherwise the user’s password would be needed (for key derivation) or some other secret held by the user’s devices (in the TPM chip or equivalent)

          • Natanael
            link
            fedilink
            English
            1
            edit-2
            1 month ago

            I’ve run a cryptography forum for 10 years. I can tell snake oil from the real deal.

            Musk’s Twitter doesn’t know how to do key distribution. The only major company using HSMs the way Musk intends to is Apple, and they have far more and much more experienced cryptographers than X does.

                  • Natanael
                    link
                    fedilink
                    English
                    01 month ago

                    If you can’t demonstrate that you know more about cryptography then me, it’s time for you to admit you’re wrong