X/Twitter Pause Encrypted DMs.
from Pro@programming.dev to technology@lemmy.world on 29 May 17:19
https://programming.dev/post/31259925

Source.

#technology

threaded - newest

tonytins@pawb.social on 29 May 17:26 next collapse

Three years later…

kami@lemmy.dbzer0.com on 29 May 17:28 next collapse

“We are excited to announce the new encrypted messaging feature that is going to be released soon™”

cron@feddit.org on 29 May 18:42 collapse

“With the latest update, you are now unable to read any encrypted PMs before may 2025. Sorry for the inconvenience.”

prole@lemmy.blahaj.zone on 30 May 13:28 collapse

More like, “for your convenience, we have decrypted all of your encrypted PMs before May 2025 and included them in this plaintext document”

ExtantHuman@lemm.ee on 29 May 17:45 next collapse

They need to add a backdoor

Pika@sh.itjust.works on 29 May 17:47 next collapse

that is my first thought as well.

“Shoot we didn’t take into consideration that GROK will need to be able to see these somehow, so now we need to redo it”

kami@lemmy.dbzer0.com on 29 May 18:17 next collapse

Bold of you to assume they weren’t already able to do it

Pika@sh.itjust.works on 29 May 18:26 collapse

I mean fair, but when Encrypted DM went live, Twitter was just starting to get into the AI field, and it was amidst a very uncertain state at that time, so I wouldn’t be surprised if they haden’t even thought of it.

Kowowow@lemmy.ca on 29 May 19:29 collapse

I just assumed it was elon trying decrypt old messages to make trump people happy so they go after individuals

givesomefucks@lemmy.world on 29 May 18:13 next collapse

People need to stop going on Twitter…

FreedomAdvocate@lemmy.net.au on 30 May 00:59 collapse

Lemmy instance admins don’t even need a backdoor to read your “private” messages btw.

givesomefucks@lemmy.world on 30 May 02:00 collapse

Obviously…

Like, you understand someone has to monitor that shit, right?

Do people think social media DMs are supposed to be secure?

FreedomAdvocate@lemmy.net.au on 30 May 02:01 collapse

I mean, ones that are E2E encrypted are

Like, you understand someone has to monitor that shit, right?

No, they don’t if they’re encrypted.

guyoverthere123@lemmy.dbzer0.com on 31 May 01:17 collapse

a? as in one?

every agency gets their own key.

eager_eagle@lemmy.world on 29 May 18:10 next collapse

⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣠⣤⣤⣤⣤⣤⣶⣦⣤⣄⡀⠀⠀⠀⠀⠀⠀⠀⠀ 
⠀⠀⠀⠀⠀⠀⠀⠀⢀⣴⣿⡿⠛⠉⠙⠛⠛⠛⠛⠻⢿⣿⣷⣤⡀⠀⠀⠀⠀⠀ 
⠀⠀⠀⠀⠀⠀⠀⠀⣼⣿⠋⠀⠀⠀⠀⠀⠀⠀⢀⣀⣀⠈⢻⣿⣿⡄⠀⠀⠀⠀ 
⠀⠀⠀⠀⠀⠀⠀⣸⣿⡏⠀⠀⠀⣠⣶⣾⣿⣿⣿⠿⠿⠿⢿⣿⣿⣿⣄⠀⠀⠀ 
⠀⠀⠀⠀⠀⠀⠀⣿⣿⠁⠀⠀⢰⣿⣿⣯⠁⠀⠀⠀⠀⠀⠀⠀⠈⠙⢿⣷⡄⠀ 
⠀⠀⣀⣤⣴⣶⣶⣿⡟⠀⠀⠀⢸⣿⣿⣿⣆⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣿⣷⠀ 
⠀⢰⣿⡟⠋⠉⣹⣿⡇⠀⠀⠀⠘⣿⣿⣿⣿⣷⣦⣤⣤⣤⣶⣶⣶⣶⣿⣿⣿⠀ 
⠀⢸⣿⡇⠀⠀⣿⣿⡇⠀⠀⠀⠀⠹⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⡿⠃⠀ 
⠀⣸⣿⡇⠀⠀⣿⣿⡇⠀⠀⠀⠀⠀⠉⠻⠿⣿⣿⣿⣿⡿⠿⠿⠛⢻⣿⡇⠀⠀ 
⠀⣿⣿⠁⠀⠀⣿⣿⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⣿⣧⠀⠀ 
⠀⣿⣿⠀⠀⠀⣿⣿⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⣿⣿⠀⠀ 
⠀⣿⣿⠀⠀⠀⣿⣿⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⣿⣿⠀⠀ 
⠀⢿⣿⡆⠀⠀⣿⣿⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⢸⣿⡇⠀⠀ 
⠀⠸⣿⣧⡀⠀⣿⣿⡇⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⣿⣿⠃⠀⠀ 
⠀⠀⠛⢿⣿⣿⣿⣿⣇⠀⠀⠀⠀⠀⣰⣿⣿⣷⣶⣶⣶⣶⠶⠀⢠⣿⣿⠀⠀⠀ 
⠀⠀⠀⠀⠀⠀⠀⣿⣿⠀⠀⠀⠀⠀⣿⣿⡇⠀⣽⣿⡏⠁⠀⠀⢸⣿⡇⠀⠀⠀ 
⠀⠀⠀⠀⠀⠀⠀⣿⣿⠀⠀⠀⠀⠀⣿⣿⡇⠀⢹⣿⡆⠀⠀⠀⣸⣿⠇⠀⠀⠀ 
⠀⠀⠀⠀⠀⠀⠀⢿⣿⣦⣄⣀⣠⣴⣿⣿⠁⠀⠈⠻⣿⣿⣿⣿⡿⠏⠀⠀⠀⠀ 
⠀⠀⠀⠀⠀⠀⠀⠈⠛⠻⠿⠿⠿⠿⠋⠁⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀⠀
    
homesweethomeMrL@lemmy.world on 29 May 18:34 next collapse

Oh man I may have to stop using this fascist propaganda service now.

bender223@lemmy.today on 29 May 18:45 next collapse

elon is the dumbest “genius” ever 🤦‍♂️

Alistaire@sopuli.xyz on 30 May 12:55 next collapse

he’s just rich but likes to pretend smart

untakenusername@sh.itjust.works on 30 May 17:19 collapse

I think there was a once a time in which he did some smart stuff (although he gets a ton a credit for stuff his employies do), but since he starting taking all those drugs he became actually insane and stupid

like theres actually no benefit of any sort to do a fucking Nazi salute

HyperfocusSurfer@lemmy.dbzer0.com on 29 May 19:55 next collapse

Do people really use DMs there?

UnderpantsWeevil@lemmy.world on 30 May 14:20 collapse

For spamming ads and scams to people? Absolutely.

notannpc@lemmy.world on 29 May 22:23 next collapse

I doubt this is news to most folks on the Fediverse, but don’t trust Twitter, Facebook, or any company whose business model is advertising to secure your private conversations.

Even if they aren’t up to no good today, it is only a matter of time until they come for your messages.

sparky@lemmy.federate.cc on 29 May 23:26 next collapse

As it happens, you shouldn’t trust Lemmy DMs either, as they’re not encrypted and can be read by instance administrators. So don’t use them to say anything that you wouldn’t be okay making public.

ferrule@sh.itjust.works on 30 May 02:21 next collapse

this should be the default stance when using any built in encryption. always separate the mode of encryption from the mode of transmission.

NotMyOldRedditName@lemmy.world on 30 May 02:43 collapse

Someone told me they are public some months ago? Like if someone wanted to look up your lemmy DMs they could.

Robust_Mirror@aussie.zone on 30 May 10:31 collapse

There was an exploit in version 0.17.0 through 0.19.0 (fixed in 0.19.1) that, from what I understand, allowed people to view DMs of anyone by reporting them, but as you can’t know the ID of a given DM you’re not part of, they couldn’t really target a specific user, but rather would just send reports to a range of potential IDs and see what comes back.

FreedomAdvocate@lemmy.net.au on 30 May 00:58 next collapse

You’re saying this on a platform that has no business model for making money and basically has no security or privacy because you’re trusting whichever random people run the instances.

notannpc@lemmy.world on 30 May 05:33 collapse

And I treat this platform accordingly. There is no expectation of privacy here. You are a private as you choose to be.

SouthEndSunset@lemm.ee on 30 May 10:16 collapse

I’ve been hearing a lot of straight up adverts about WhatsApp recently, which I found interesting.

prole@lemmy.blahaj.zone on 30 May 13:26 collapse

I saw a WhatsApp ad on Prime. And it was focused on the encryption aspect. “WhatsApp can’t even read your messages” or whatever. Was weird.

SouthEndSunset@lemm.ee on 30 May 16:24 collapse

I’m hearing a lot of that on the radio.

iconic_admin@lemmy.world on 30 May 00:10 next collapse

So… they’re definitely adding some spying capabilities.

neukenindekeuken@sh.itjust.works on 30 May 13:13 collapse

100%. If it was purely a migration, it wouldn’t need to have downtime. There’s ways to replay events and eventually catch a system up (eventual consistency models).

This feels more like they’re adding backdoor into their encryption algorithms for government agencies.

Given who musk is, and what he’s done the last year and who he’s hanging out with in this admin, that’s a near sure thing.

FreedomAdvocate@lemmy.net.au on 30 May 01:03 next collapse

Before too many more conspiracy theorists jump in - it looks like they’re replacing encrypted DMs with “chat” where EVERYTHING is encrypted:

x.com/P4mui/status/1927829200599224624

<img alt="" src="https://lemmy.net.au/pictrs/image/8236f697-91b9-4a3a-a35f-9ff14ea96221.png">

sik0fewl@lemmy.ca on 30 May 01:54 next collapse

They’re moving to IRC?

FreedomAdvocate@lemmy.net.au on 30 May 02:02 next collapse

Haha yeh that person probably should have seen if XChat was already taken, but you know what they meant.

tarknassus@lemmy.world on 30 May 08:03 collapse

Last update 2010. Makes me sad. Good times using IRC, I should find a modern program and get back on there.

sik0fewl@lemmy.ca on 30 May 13:33 next collapse

Damn. That’s probably the last time I used it, too.

wookiepedia@lemmy.world on 30 May 14:45 collapse

irssi

Natanael@infosec.pub on 30 May 01:56 collapse

Will they be using a modern encryption protocol this time?

KulunkelBoom@lemm.ee on 30 May 02:19 next collapse

They’re being rerouted to a more “secure” storage facility. I believe it’s Kaspersky’s.

driving_crooner@lemmy.eco.br on 30 May 18:04 collapse

Is not Kaspersky part of the US government embargo on Russian companies?

Bogasse@lemmy.ml on 30 May 05:05 next collapse

while we work on making improvements

🤣

The fact that he tried to make it like there is a reasonable reason is delightful.

neukenindekeuken@sh.itjust.works on 30 May 13:12 collapse

“Improvements” = Adding backdoors to their encryption for agency spying networks.

This is how that works.

UnderpantsWeevil@lemmy.world on 30 May 14:19 collapse

I’m more than confident that Twitter already had a backdoor for encrypted DMs.

However, I would bet cash money that the current administration has lost the institutional knowledge of how to use it. So they’re having to reinvent the wheel, most likely by injecting a bunch of new bugs and sloppily implemented hacks.

echodot@feddit.uk on 30 May 17:31 collapse

I just like the idea that previous administrations just delete all of the documentation on the way out, rather like a fired sysadmin worker deleting all their automation scripts. “Work it out for yourself”

MolecularCactus1324@lemmy.world on 30 May 16:38 next collapse

I thought they disabled DMs when some influencer refused to have Elon Musk’s babies and shared her DMs with a friend

starkzarn@infosec.pub on 30 May 18:23 next collapse

They misspelled “backdoors.”

ne0phyte@feddit.org on 30 May 20:13 next collapse

I would not trust any company/website to properly encrypt any important messages in the first place so I don’t care whether they add a backdoor (and I’ve never had a Twitter account anyway).

…but it sounds like a really shitty development/release process to me. Why would you disable something while whatever is to come in its place is not ready yet?

Why not do the development first and then migrate when it’s actually ready lol

Lifter@discuss.tchncs.de on 01 Jun 06:17 collapse

There may be several reasons for this. If I had to guess, they found a critical flaw and had to shut it down for security reasons.

nebulaone@lemmy.world on 31 May 07:49 next collapse

Just use PGP everywhere, it doesn’t matter where you chat then.

FreedomAdvocate@lemmy.net.au on 31 May 22:13 collapse

And there we have it - new fully encrypted chat launched on X.

<img alt="" src="https://lemmy.net.au/pictrs/image/69131bc9-aebb-44f9-9746-69c7aca7a49e.jpeg">