Twitter’s Encrypted DMs Lead Appeared to Falsely Claim Security Audit


  • Twitter announced its new encrypted DMs feature last week.
  • Elon Musk and the company both warned that it wasn’t fully secure yet so shouldn’t be trusted.
  • The project’s lead said it had been audited by a cybersecurity firm; company sources disputed this, per Platformer.

A Twitter engineer leading the platform’s new encrypted messaging feature for paid users appeared to falsely claim that it had been audited by a top cybersecurity firm, Platformer reported.

When Twitter released the feature last week, it came with several disclaimers that it wasn’t yet fully secure.

“The acid test is that I could not see your DMs even if there was a gun to my head,” Elon Musk wrote on Twitter – adding that the company wasn’t quite at that level. “Try it, but don’t trust it yet,” he later said.

The idea is that by having DMs encrypted, text can only be read by participants of that conversation – as is the case on platforms such as WhatsApp. 

Twitter said in a blog post that this new feature could be vulnerable to “man-in-the-middle attacks” which would let “a malicious insider, or Twitter itself as a result of a compulsory legal process” access users’ DMs.

According to Platformer, Christopher Stanley – a former SpaceX staffer who now runs Twitter’s security engineering and the encrypted DMs project – said that this new feature had been audited by a cybersecurity firm called Trail of Bits in a now-deleted tweet.

“A white paper will be published soon,” Stanley reportedly Tweeted. “I had [cybersecurity firm] Trail of Bits audit our implementation. Dan Guido and those folks are badass” – referring to its CEO who has also advised the Commodity Futures Trading Committee.

But Twitter hadn’t even signed a contract with the firm yet, unnamed company sources told Platformer.

According to the tech newsletter, that’s because Twitter keeps laying off the procurement staff who would handle such deals.

Since Musk took over the company last October, Twitter’s workforce has fallen roughly 90% to around 1,000 employees, Insider’s Kali Hays reported. These layoffs have caused at least one major outage on Twitter

Insider contacted Twitter for comment. The company responded with an automated message that didn’t address the inquiry.

Trail of Bits did not immediately respond to Insider’s request for comment which was sent outside US working hours.





Source link: https://www.businessinsider.com/twitter-encrypted-dms-head-appeared-to-falsely-claim-security-audit-2023-5

Sponsors

spot_img

Latest

Bulls have more ‘work to do,’ could wait on Lillard, Harden trades

So far this summer, the Chicago Bulls have stayed involved, especially in free agency. Not only did they bring back Nikola Vucevic and...

States Try to Reform Prostitution Laws — for Better and Worse

State lawmakers in at least six states have recently introduced bills related to sex work. Some of these measures would decriminalize prostitution, while...

Trudeau knows there’s trouble on the horizon

Trudeau’s campaign-style tone is unmistakable. “There are two leaders today that you have to choose between,” he said in reference to Conservative Leader Pierre...

Tommy Fury likened to Romelu Lukaku as Mauricio Pochettino ruthlessly hauls him off at Soccer Aid

Tommy Fury had a short, but not very sweet cameo at Soccer Aid as Mauricio Pochettino hauled him off at Old Trafford. The British...

Joe Marler’s brutal ‘fiction or non-fiction’ Danny Cipriani quip

Joe Marler has taken issue with Danny Cipriani’s claim that there is no room for individuals in the modern game. The colourful...