Skip to content
Net SEO Marketing

Net SEO Marketing

Primary Menu
  • Home
  • Contact
  • Privacy Policy
    • Consent
    • Terms of Use
  • apps
    • Social
  • Artificial Intelligence
  • e-commerce
  • robotics
  • Home
  • Social
  • X’s New Encrypted Chat: Why You Should Not Trust It Yet
  • Social

X’s New Encrypted Chat: Why You Should Not Trust It Yet

nets45 September 5, 2025
twitter-x-logo-musk-2

X, the platform formerly known as Twitter, has officially launched its new encrypted messaging feature, dubbed “Chat” or “XChat,” but security experts are urging users to remain skeptical of its true privacy protections.

While the company claims this feature provides end-to-end encryption—ensuring that only the sender and receiver can access message content—cryptography researchers argue the current implementation is significantly less secure than industry standards like Signal.

The Flawed Key Management System

The core of the issue lies in how X handles encryption keys. When users activate XChat, they are prompted to create a four-digit PIN. This PIN is used to encrypt a private key, which is then stored directly on X’s servers. In contrast, services like Signal store private keys exclusively on the user’s local device, preventing the service provider from ever having access to the means of decryption.

Security researcher Matthew Garrett, who analyzed the service during its rollout, notes that without guaranteed use of Hardware Security Modules (HSMs), X could theoretically tamper with or brute-force these four-digit keys. While an X engineer claimed on social media that HSMs are in use, the company has yet to provide public verification, leaving the system in a state of “trust us” security.

Vulnerability to Insider Threats

Perhaps most concerning is the acknowledgment by X itself, documented on their support page, that the service could allow “a malicious insider or X itself” to compromise conversations. This risk of an “adversary-in-the-middle” (AITM) attack effectively undermines the primary promise of end-to-end encryption.

Because X controls the distribution of public keys, users have no way to verify if the company has surreptitiously swapped a key to facilitate eavesdropping. Furthermore, the lack of an open-source implementation—unlike the transparent, fully documented model of Signal—prevents the security community from auditing the code. X has stated plans to open-source the implementation and release a technical whitepaper later this year, but these remain promises for the future.

Missing “Perfect Forward Secrecy”

The service also lacks “perfect forward secrecy.” This essential cryptographic mechanism ensures that each message is encrypted with a unique key. Without it, if a user’s private key is ever compromised, an attacker could potentially decrypt not just current messages, but all historical conversations as well. X has officially admitted to this limitation.

Experts like Matthew Green, a cryptography professor at Johns Hopkins University, remain unconvinced. “For the moment, until it gets a full audit by someone reputable, I would not trust this any more than I trust current unencrypted DMs,” Green stated.

As of now, X has not responded to multiple requests for comment regarding these security concerns.

Continue Reading

Previous: Snapchat Launches AI Lens: Create AR Images With Text Prompts
Next: Are Bad Incentives Fueling AI Hallucinations?

Related News

GettyImages-155283357
  • Social

Beehiiv Launches Webinar Tools and Custom Paywalls

nets45 May 6, 2026
X-and-Threads-GettyImages-1763609384
  • Social

X Shuts Down Communities Amid Low Engagement and Spam

nets45 May 5, 2026
social-media-icons
  • Social

Social Media Scams Cost Americans $2.1B in 2025

nets45 April 28, 2026

artificial intelligence news

OpenAI Planning AI-Powered Phone to Replace Traditional Apps GettyImages-2206295463

OpenAI Planning AI-Powered Phone to Replace Traditional Apps

May 3, 2026
DeepMind Alum David Silver Raises $1.1B for AI Startup GettyImages-2233739454

DeepMind Alum David Silver Raises $1.1B for AI Startup

April 30, 2026
OpenAI and Microsoft End Cloud Feud Over $50B Amazon Deal GettyImages-2214107176

OpenAI and Microsoft End Cloud Feud Over $50B Amazon Deal

April 29, 2026
Apple’s Robotics Future: John Ternus’ Next Big Hardware Bet GettyImages-2264522469

Apple’s Robotics Future: John Ternus’ Next Big Hardware Bet

April 25, 2026
ComfyUI Hits $500M Valuation to Revolutionize AI Control ComfyUI-Co-founders-1

ComfyUI Hits $500M Valuation to Revolutionize AI Control

April 24, 2026
Nothing Launches Essential Voice: AI Dictation for Your Phone IMG_2376-rotated-1

Nothing Launches Essential Voice: AI Dictation for Your Phone

April 24, 2026

e-commerce news

jack-conte-sxsw-1
  • e-commerce

Patreon CEO Blasts AI ‘Fair Use’ Claims as Bogus

nets45 March 18, 2026
RedNote-GettyImages-2193805638
  • e-commerce

Apple Quietly Slashes App Store Commissions in China

nets45 March 13, 2026
android-GettyImages-458108827
  • e-commerce

Google Settles With Epic Games, Slashes Play Store Fees to 20%

nets45 March 4, 2026
X-and-Threads-GettyImages-1763609384
  • e-commerce

X Launches Official ‘Paid Partnership’ Labels for Creators

nets45 March 2, 2026
  • e-commerce

eBay Slashes 800 Jobs: 6% of Workforce Cut Amid Restructuring

nets45 February 26, 2026

See before you leave

GettyImages-155283357
  • Social

Beehiiv Launches Webinar Tools and Custom Paywalls

nets45 May 6, 2026
X-and-Threads-GettyImages-1763609384
  • Social

X Shuts Down Communities Amid Low Engagement and Spam

nets45 May 5, 2026
GettyImages-2206295463
  • Artificial Intelligence

OpenAI Planning AI-Powered Phone to Replace Traditional Apps

nets45 May 3, 2026
GettyImages-2233739454
  • Artificial Intelligence

DeepMind Alum David Silver Raises $1.1B for AI Startup

nets45 April 30, 2026
Copyright © All rights reserved. | MoreNews by AF themes.