Secure messaging arrives on Twitter – sort of. ‘Don’t trust it yet,’ Musk warns

May 11, 2023, 3:36 PM

FILE - The Twitter splash page is seen on a digital device, April 25, 2022, in San Diego. Twitter l...

FILE - The Twitter splash page is seen on a digital device, April 25, 2022, in San Diego. Twitter launched encrypted messaging Wednesday, May 10, 2023, offering select users the ability to communicate more securely. But its new service is much more of a baby step than a giant leap forward. (AP Photo/Gregory Bull, File)
Credit: ASSOCIATED PRESS

(AP Photo/Gregory Bull, File)

SAN FRANCISCO (AP) — Twitter launched encrypted messaging Wednesday, offering select users the ability to communicate more securely. But its new service is much more of a baby step than a giant leap forward.

For starters, it lacks basic protections that security experts consider essential for shielding messages from hackers and other prying eyes. Senders and receivers must also be subscribed to Twitter’s Blue service for $11 a month ($8 for desktop-only) or otherwise affiliated with an organization “verified” by Twitter for $1,000 a month plus $50 per user.

The company’s official message announcing the rollout promised additional features soon. But CEO Elon Musk offered his own caution via a tweet: “ Try it, but don’t trust it yet.

WHAT IS ENCRYPTED MESSAGING AGAIN?

Ordinary messages sent across the internet, whether by email, direct message, Twitter or other means — are generally vulnerable to interception that could allow other people or organizations to read them. That includes the companies offering the message services. Those companies can also be required to produce user messages in response to a legal subpoena or court order.

Encryption technology offers protection against spies and nosy online neighbors by encoding messages so that only the sender and the recipient can decipher them.

SO HOW DOES TWITTER’S NEW ENCRYPTION STACK UP?

Not super well. The gold standard in secure messaging is set by services such as Signal and ProtonMail, which use strong “end-to-end” encryption to shield messages so that no one else — not even the companies themselves — can read them.

Twitter’s service doesn’t currently do that. For the moment, its encrypted messages are vulnerable to a so-called “man-in-the-middle” attack that allows an attacker to insinuate themselves into an encrypted conversation to listen in and even modify messages as they’re sent. Twitter itself, in fact, has the ability to do this.

“The acid test is that I could not see your DMs even if there was a gun to my head,” Musk tweeted on Tuesday. But Twitter isn’t there yet.

Twitter also doesn’t offer any way to report encrypted messages for harassment or abuse, although it will be possible to block individual senders.

ARE THERE OTHER DRAWBACKS?

Yes. For instance, Twitter’s encrypted messages can only be sent to another individual. Twitter says it will “soon” be expanding encryption to groups. Encrypted messages are also limited to text and links; photos, video and other attachments aren’t supported yet, the company says.

Twitter encryption also doesn’t provide what’s called “forward secrecy,” which would prevent an attacker who gets hold of a user’s private key from using it to read earlier and subsequent messages.

In its official document, Twitter says forward secrecy techniques aren’t compatible with user expectations that they’ll always be able to obtain their historical messages from the cloud. As a result, the company doesn’t plan to offer forward secrecy at all.

A final issue: Users won’t have any way to make encrypted messages a default setting; they’ll have to deliberately choose encryption each time they start a new conversation.

National News

FILE - This booking photo provided by the Platte County Sheriff's Office shows Lorna Roxanne Green ...

Associated Press

College student accused of setting fire to Wyoming’s only abortion clinic to enter plea

CHEYENNE, Wyo. (AP) — A college student who authorities say admitted setting fire to a building slated to become Wyoming’s only full-service abortion clinic was scheduled to appear in federal court Friday to enter a plea to an arson charge. Lorna Roxanne Green, 22, told investigators that she opposes abortion and was experiencing anxiety and […]

21 hours ago

Associated Press

Iowa officials expected to detail demolition plans for partially collapsed building

DES MOINES, Iowa (AP) — Plans to demolish a partially collapsed six-story apartment building in Iowa could become clearer Friday, five days after much of the structure crumbled and left three tenants missing and feared dead. Davenport Mayor Mike Matson said Thursday he expected to announce a company “to do a very systematic approach to […]

21 hours ago

This May 26, 2023, photo provided by the Jennifer Schuh shows a Mastodon Tooth in the sand at an Ap...

Associated Press

Woman walking on California beach finds ancient mastodon tooth

APTOS, Calif. (AP) — A woman taking a Memorial Day weekend stroll on a California beach found something unusual sticking out of the sand: a tooth from an ancient mastodon. But then the fossil vanished, and it took a media blitz and a kind-hearted jogger to find it again. Jennifer Schuh found the foot-long (.30-meter) […]

21 hours ago

FILE - Clouds hover over the Oregon Capitol, Jan. 11, 2018, in Salem, Ore. Oregon Senate Democrats ...

Associated Press

Oregon Democrats vote to fine absent senators amid GOP walkout

SALEM, Ore. (AP) — Oregon Senate Democrats plan to start fining their absent colleagues amid a month-long Republican walkout, a move they hope will pressure boycotting lawmakers to return to the chamber as hundreds of bills languish amid the partisan stalemate. In a procedural move Thursday, Democrats voted to fine senators $325 every time their […]

21 hours ago

Associated Press

Judge delays first criminal trial in Elijah McClain’s death over objections of prosecutors

DENVER (AP) — A judge agreed Thursday to delay the first criminal trial in the death of Elijah McClain, a 23-year-old Black man who died after being stopped by police in a Denver suburb, forcibly restrained and injected with a powerful sedative nearly four years ago. Lawyers for the two officers previously scheduled to go […]

21 hours ago

FILE - Sections of a USA Today newspaper are displayed Aug. 5, 2019, in Norwood, Mass. Journalists ...

Associated Press

Journalists to strike June 5 at the largest US newspaper chain

Journalists across the U.S. will walk off their jobs next week at roughly two dozen newsrooms run by Gannett, the largest newspaper chain in the U.S., their union said Thursday. The mostly one-day strike, which will start June 5, aims to protest Gannett’s leadership and cost-cutting measures imposed since its 2019 merger with GateHouse Media. […]

21 hours ago

Sponsored Articles

Internet Washington...

Major Internet Upgrade and Expansion Planned This Year in Washington State

Comcast is investing $280 million this year to offer multi-gigabit Internet speeds to more than four million locations.

Compassion International...

Brock Huard and Friends Rally Around The Fight for First Campaign

Professional athletes are teaming up to prevent infant mortality and empower women at risk in communities facing severe poverty.

Emergency Preparedness...

Prepare for the next disaster at the Emergency Preparedness Conference

Being prepared before the next emergency arrives is key to preserving businesses and organizations of many kinds.

SHIBA volunteer...

Volunteer to help people understand their Medicare options!

If you’re retired or getting ready to retire and looking for new ways to stay active, becoming a SHIBA volunteer could be for you!

safety from crime...

As crime increases, our safety measures must too

It's easy to be accused of fearmongering regarding crime, but Seattle residents might have good reason to be concerned for their safety.

Comcast Ready for Business Fund...

Ilona Lohrey | President and CEO, GSBA

GSBA is closing the disparity gap with Ready for Business Fund

GSBA, Comcast, and other partners are working to address disparities in access to financial resources with the Ready for Business fund.

Secure messaging arrives on Twitter – sort of. ‘Don’t trust it yet,’ Musk warns