[TAG0][TAG1]
- Twitter launched its new encrypted DMs last week.
- Elon Musk, as well as the company, both warned that it was not fully secure and shouldn't be relied upon.
- Platformer reports that the project's leader claimed it was audited. However, company sources have denied this.
Platformer reported that a Twitter engineer who was leading the new encrypted messaging service for paid users falsely claimed it had been audited.
Twitter's feature was released last week with several disclaimers stating that it is not yet secure.
Elon Musk said on Twitter that the acid test was that he couldn't see your DMs if a gun were held to his head. He added that Tesla wasn't yet at this level. Elon Musk said later, "Try it but don't yet trust it."
WhatsApp and other platforms like it encrypt DMs so that only participants in the conversation can read them.
Twitter stated in a blog that the new feature was vulnerable to "man in the middle attacks". This would allow "a malicious insider or Twitter as a result a mandatory legal process" to access users' DMs.
Platformer reports that Christopher Stanley, a former SpaceX employee who now heads Twitter's Security Engineering and the encrypted DMs Project, said in a deleted tweet that a cybersecurity company called Trail of Bits had audited this new feature.
Stanley tweeted, "A whitepaper will be published shortly." I had [cybersecurity company] Trail of Bits review our implementation. Dan Guido, the CEO of this firm who also advises the Commodity Futures Trading Committee is badass.
Platformer reported that Twitter had not yet signed a contract.
The tech newsletter claims that this is because Twitter continues to lay off its procurement staff, which would normally handle these deals.
Insider's Kali Hays reports that since Musk took over Twitter last October, Twitter has reduced its workforce by 90%, to approximately 1,000 employees. The layoffs are responsible for at least one major Twitter outage.
Twitter was contacted by Insider for a comment. Twitter responded to Insider's inquiry with an automated response.
Insider sent a comment request to Trail of Bits outside US business hours. They did not respond immediately.
—————————————————————————————————————————————
By: psyme@insider.com (Pete Syme)
Title: A top Twitter staffer said its new encrypted DM feature was tested by a cybersecurity firm, but insiders say the company never signed a formal deal due to layoffs – report says
Sourced From: www.businessinsider.com/twitter-encrypted-dms-head-appeared-to-falsely-claim-security-audit-2023-5
Published Date: Tue, 16 May 2023 11:05:27 +0000
Leave a Reply