Twitter’s DM encryption is a modest security improvement over the status quo
platformer.news
platformer.news
Overall I think my original conclusion still holds. If you're going to use Twitter DMs, turning on encryption is better than not doing so. But right now it's protecting against someone with opportunistic access to the Twitter prod databases, not an advanced attacker or someone with subpoena powers, and if you have to worry about that you should definitely use Signal instead.
(Edit: someone asked whether working on fruitflies would have been more relaxing than reverse engineering weird encryption, and I wrote this reply, but they'd deleted the comment. You get the reply anyway:
Reverse engineering fruitflies means reverse engineering something that's almost entirely undocumented, what documentation does exist is frequently wrong, that has almost 4 billion years of tech debt, that relies on self-modifying code, executed on a series of components that aren't fully deterministic, that can only be bootstrapped from existing fruitflies, that has no debugger, that had no functional specification, that has an instruction set where the behaviour of an instruction can depend on the three dimensional structure of the encoding of those instructions and so be influenced by instructions that are several thousand (if not million) instructions away in what looks like an entirely separate compilation unit, and if you change the temperature or humidity or any number of other apparently irrelevant factors will just behave entirely differently. And, if you fuck up, you suddenly have a room full of fruitflies.
So, yes, reverse engineering Java is definitely more relaxing.)
Because fruit flies are a model organism, they are therefore one of the most studied organisms in the world. We arguably know more about fruit flies than humans and try to extrapolate what we know about fruit flies to humans (with varying success).
I guess my point is that reverse engineering fruit flies is actually very well documented (in the biological literature, and even textbooks, very well established for decades now).
Fruit flies are used because it is easy to do genetics on them. Genetics means causing random mutations, selecting for something, then breeding them true to make a mutant strain, then crossbreeding, making further mutants, and doing experiments on all the results.
Each of those mutant strains is part of your scientific 'capital', something you've invested in and want to extract returns from. You have to preserve it. And to preserve it, you need to transfer ('flip') flies of that strain to a fresh tube of banana paste every three weeks. For all of your strains. Without ever missing a flip.
So i'm not sure that working on fruit flies is relaxing, exactly. Maybe if you can afford a technician to look after them for you!
All I’m saying is that twitter, if you’re reading this, know that I have the blue checkmark ;) and that I’m available for pentesting your e2e encryption implementation!
Also, trust in the privacy of messages is the entire point of E2E encrypted DMs. It's a pretty dumb strategy to launch that feature and then walk it back with a "oops we're beta testing, don't trust that while privacy thing yet." So either Twitter/Elon has a dumb strategy, or they're (still) making wildly silly blunders as a result of self-inflicted wounds. Either way, pretty compelling arguments to never trust this feature even once they say you can.
For those who already use Twitter DM's (which is a lot of people), this is an improvement.
>BigCivilEngineeringFirm says the new road bridge opened yesterday is an early version that shouldn't be trusted yet
There are many, many software developers. There are vanishingly few software engineers
When the entities that affect the company's existence the most i.e. regulators and advertisers are asking for more thoughtful, measured and safe changes.
And instead he's obsessed with adding end-user features which based on the woeful Twitter Blue subscription numbers seems like a dead-end strategy.
source: NYT 2019 investigation into the link between the rise of social media and the spread of CSAM
https://www.nytimes.com/interactive/2019/11/09/us/internet-c...
> Users don't benefit from this change.
Twitter blocked links to the New York Post in DM's over their Hunter Biden story. Clearly all users would benefit if they don't MITM 1:1 DM's.
I'm not sure why either.
Twitter is built around public communication.
Why would I pay for encrypted private communication when I already use better existing solution for free ? And even if I pay it's useless unless others pay too (what a fail might have been interesting if it worked as soon as one party was verified).
With this feature they go from a shitty DM to a shitty sometime encrypted DM.
Wouldn't call this a nobrainer ...
The good thing about Twitter DMs is that they don't expose your phone number which means you can - reasonably safely - converse with strangers.
There is a lot more friction involved in getting an anonymous prepaid number, and them proving your identity. On Twitter those issues are solved.
> the metadata isn't encrypted
I wouldn't trust this if I was Snowden, but I would trust this if I was a corporate whistleblower and wanted to get information out to jousnalists as soon as possible.
Him micromanaging a business is a death knell. The guy is probably awake all the time from uppers, and you don't make good decisions where you are sleep-deprived.
If Twitter could still be traded, he could announce his X app with some broken features, buy lots of ads, pay for influencers and reviews, and Twitter price would go up. And he's the kind of person who we know could totally do it.
None of that is mitigated by the fact that Tesla is still up 718% since 2018, not everybody invested back then, nor is everybody, especially shorts and their counterparts in thier trades, long term investors.
Your question makes no sense without price information, and even then, that's way too broad a target to reflect the knowledge of a guy, where just listening is more than enough
b) His track record in general is not without faults.
c) His track record with Twitter is clear for everyone to see. Revenue has plummeted, Twitter Blue subscription numbers are just embarrassing and BlueSky is every day attracting more and more key content creators. Twitter is slowly but surely going to end up being nothing more than a Truth Social / Gab clone.
That's going to be a dramatic decrease in costs. Their revenue since is going to be difficult if not impossible to fairly assess. Many (most?) of the largest advertisers like Apple/Amazon have returned, but likely with discounted enticements which, to my knowledge, are not public. So all one can do is speculate. I think the only fair conclusion is that it's hardly doomsday for Twitter, but it's also not quite time for a victory parade either.
I genuinely hope alternatives, especially decentralized ones, succeed. Competition improves everybody. But the reason Elon spent $40 billion on Twitter is not for the software, but for the users. Network effect is seemingly impossible to overcome, regardless of the merit of a site.
Mainly because of Tesla, which is overvalued also according to him.
>bitter commenter.
This fits for Elon too.
https://fortune.com/2023/05/10/elon-musk-twitter-texas-mall-...
These companies notoriously do not delete anything ever. I am sure that even the things they are required to delete by law are removed, compressed and stashed somewhere.
All the technical details of it are kind of moot, because fundamentally any attack on Twitter won't be technical, it'll be a practical application of pressure on Musk.
But that's not fast enough because it's not perfect yet?
Do we think there's more dead wood Imposters that needs to be fired at Twitter to get progress even faster?
> Then they'd have the corresponding private key, and would be able to obtain the message encryption key.
This is technically wrong or badly worded. Is it just saying since you run their software on your device they could steal your private key? Same as WhatsApp or Signal? Not sure I get this point. If app developer turns evil and no one notices you are always stuffed.
Could you explain why?
> Is it just saying since you run their software on your device they could steal your private key?
No. It's saying that because there's no indication of which keys the conversation key is being sent to, if Twitter added an additional public key to a users's set of registered keys, anyone who initiated a DM with that user would have no way of knowing that they were sending a copy of the conversation key to Twitter. This doesn't involve any modification of the client code.
Musk has already proven he is more likely to snitch on users for the government than the previous admin.
From there you can only extrapolate that this will be delivered with a government backdoor on the app side. If Musk actually manages to lure in whistleblowers to his platform with these antics those whistleblowers will have their asses hanging in the wind waiting for a government assistance request. Hopefully they arent as stupid as to trust musk.