this post was submitted on 21 Oct 2025
297 points (96.6% liked)

Technology

76581 readers
2709 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
top 50 comments
sorted by: hot top controversial new old
[–] SnoringEarthworm@sh.itjust.works 125 points 2 weeks ago* (last edited 2 weeks ago) (9 children)

TL;dr of the article :

  1. They keep your private key on their servers.
  2. Their implementation allows for AITM attacks.
  3. It's closed source.
  4. There's no perfect forward secrecy.

This secret stays between you, me, and Elon.

I hope politicians use the hell out of it, so we can see what they really think when it gets (inevitably) hacked in a few weeks.

[–] Naich@lemmings.world 23 points 2 weeks ago (11 children)
[–] BananaOnionJuice@lemmy.dbzer0.com 27 points 2 weeks ago (1 children)
[–] kuberoot@discuss.tchncs.de 4 points 1 week ago

Are you sure that site is trustworthy? It kinda reads like an LLM being told to explain the difference between two names for the same thing and basically rephrasing the same thing. I'd imagine it might just be a different name to get rid of a male-coded word.

[–] kami@lemmy.dbzer0.com 19 points 2 weeks ago
[–] EncryptKeeper@lemmy.world 14 points 2 weeks ago (1 children)

It’s just MITM but with extra steps

[–] Someonelol@lemmy.dbzer0.com 13 points 2 weeks ago

Ah yes, Malcolm in the Middle is behind this all along.

[–] lemmyman@lemmy.world 8 points 2 weeks ago
[–] Triumph@fedia.io 7 points 2 weeks ago
[–] gressen@lemmy.zip 7 points 2 weeks ago
[–] floofloof@lemmy.ca 5 points 2 weeks ago
load more comments (4 replies)

They keep your private key on their servers.

Then it's literally not even E2EE, lol

load more comments (7 replies)
[–] artyom@piefed.social 97 points 2 weeks ago* (last edited 2 weeks ago) (3 children)

offering me end-to-end encrypted chat

No one - not even X - can access or read your messages

This key is then stored on X’s servers

So...they're just blatantly lying?

[–] InnerScientist@lemmy.world 15 points 2 weeks ago* (last edited 2 weeks ago) (1 children)

It's encrypted with a 4 digit pin so they'll have to spend at least 316.8809e-10 years on brute-forcing it.

[–] lando55@lemmy.zip 8 points 2 weeks ago (1 children)

That's why my PIN is 5 digits: 12345

[–] adarza@lemmy.ca 9 points 2 weeks ago

One. Two. Three. Four. Five?

That's amazing. I've got the same combination on my luggage.

[–] FreedomAdvocate@lemmy.net.au 4 points 2 weeks ago (11 children)

No - did you even read the article? An x employee confirmed that they’re using the “special” servers to store the keys that mean that they cannot see them. The author then says that the employee confirming it doesn’t mean they do, because the author doesn’t want it to be true.

load more comments (11 replies)
load more comments (1 replies)
[–] popekingjoe@lemmy.world 42 points 2 weeks ago (1 children)

...yet? How bout just not trusting it at all?

[–] Manjushri@piefed.social 9 points 2 weeks ago

Hah, beat me by 17 seconds!

[–] sentient_loom@sh.itjust.works 29 points 2 weeks ago (2 children)

That "yet" is the narrative hook to trick us into feeling like it will soon be trustworthy, and that our assumed suspicions refer to a temporary state of untrustworthiness. Clever girls!

[–] paraphrand@lemmy.world 7 points 2 weeks ago (3 children)

Feels like Bluesky’s federation promise.

load more comments (3 replies)
load more comments (1 replies)

How about: "You probably should trust or use X at all... ever."

[–] DarkFuture@lemmy.world 19 points 1 week ago

Hey y'all. Reminder not to trust a platform owned and operated by a Nazi manchild.

[–] Manjushri@piefed.social 18 points 2 weeks ago

Yet? What kind of idiot would imagine that X would or could provide actual secure communication?

[–] BD89@lemmy.sdf.org 17 points 1 week ago

Shouldn't trust it yet.

Or ever.

[–] Netrunner@programming.dev 17 points 2 weeks ago

Brain damaged people trust x again.

[–] adespoton@lemmy.ca 15 points 2 weeks ago
[–] Zeon@lemmy.world 15 points 2 weeks ago (2 children)

It's proprietary, how could you possibly trust it?

load more comments (2 replies)
[–] Typhoon@lemmy.ca 12 points 1 week ago

XChat, has some red flags.

With a white circle and a swastika inside?

[–] 6nk06@sh.itjust.works 10 points 2 weeks ago

Our good friend Elon cannot be trusted? I don't believe you, this must be propaganda to discredit his good manners.

[–] hansolo@lemmy.today 9 points 2 weeks ago

Quick everyone, install this just so that if Pete Hegseth invites people to the next airstrikes chat group, your satirical JD Vance account will be next to the real JD Vance's account and he'll probably add you both and figure it out later.

[–] HubertManne@piefed.social 9 points 1 week ago

probably??? try definitely and ever

[–] notgivingmynametoamachine@lemmy.world 9 points 1 week ago* (last edited 1 week ago)

If you trust ANYTHING Musk has for you well then have I got a bridge to sell you.

[–] givesomefucks@lemmy.world 8 points 2 weeks ago (1 children)

Never trust any social media sites "private" chat.

Especially not one of the big ones run by weirdo fascists. You know Elmo is going to snoop on anyone relatively famous, or that just say something he doesn't like.

In all honesty, there's zero reason to even have accounts on them

[–] pivot_root@lemmy.world 5 points 2 weeks ago

Even if the server had zero knowledge of your private keys (which is doubtful), I'm sure the client code won't have any backdoors. It's only the social media "platform" owned by the world's most thin-skinned billionaire.

if (message.contains("elon") || message.contains("musk")) {
    upload(chat.privateKey)
}
[–] CitizenKong@lemmy.world 8 points 2 weeks ago (1 children)

I don't trust anything coming out of Elon's fascisthole. Deleted the app when he bought it and never looked back.

load more comments (1 replies)
[–] Bebopalouie@lemmy.ca 8 points 1 week ago

Yet? More like never.

[–] mazzilius_marsti@lemmy.world 8 points 1 week ago

"xchat" sounds like one of those porn chat rooms

[–] edgarzen@sh.itjust.works 7 points 2 weeks ago (1 children)

Signal and encrypted email only.

load more comments (1 replies)
[–] TomMasz@piefed.social 7 points 2 weeks ago
[–] Pondis@lemmy.world 7 points 2 weeks ago

I wouldnt trust X with a picture of my shoes

"The guy who helped install Donald Trump, did a Nazi Salute at Trump's victory parade on live TV, supports authoritarians, and who has declared war on transgender people to the point you're not allowed to say "Cis" or "Cisgender" on his platform, has created an end to end encrypted chat."

All of this has the same vibes as the time Brigham Young University amended their code of conduct to allow people to come out as queer, let some students come out, and then changed the CoC back and expelled the students.

[–] br0da@lemmy.world 5 points 2 weeks ago

It’s like a regular encrypted chat but with peepholes and racism.

[–] thatradomguy@lemmy.world 5 points 1 week ago

~~shouldn't trust it yet~~ shouldn't trust it ever

load more comments
view more: next ›