Live data from Hacker News

X's new "encrypted" XChat feature doesn't seem to be any more secure

theregister.com

71–80 of 86 posts

Re: X's new "encrypted" XChat feature doesn't seem to be any more secure

#71
post #38
post #29

Earlier quoted context omitted.

It sounds like an offhand comment that we shouldn’t read much into. Bitcoin’s creator demonstrated an impressive mastery of cryptography—- it was made to be extremely resilient (including to quantum computing) and no one has ever broken it despite billions of dollars being on the line. Maybe Musk meant to say that he thinks his product will be similarly resilient. He might also mean that the secp256k1 elliptic curve…

> You can read anything with the assumption that the writer is an absolute idiot, but I’d give the world’s richest man more credit than that. Before the pandemic, I would've said similar, even despite some of his errors of judgement. Since then, and the trend started earlier, it has become difficult to ignore that (1) he responds poorly to experts contradicting him, and (2) outside his actual domains of expertise (ro…

At best, he brings technical ideas. Not implementation.

Re: X's new "encrypted" XChat feature doesn't seem to be any more secure

#72
post #23
post #4

Earlier quoted context omitted.

Sure we know that we should not trust anything Musk or X claims? By now? I mean, come on.

Some things Musk claimed have happened, others have not. For example, he promised that they would release a satellite Internet platform that was better than most of the others, and they did. On the other hand, he promised that Grok 3 would be massively better than ChatGPT, and it turned out to be comparable at best.

Sure, ill sell you this broken clock. Its been shown to know atleast two times a day.

Re: X's new "encrypted" XChat feature doesn't seem to be any more secure

#73

Earlier quoted context omitted.

- I have public chat that user can chatting in public room (seems like I dont need for this one) - then notification service is probably something I want to E2EE then, but Idk about performance hit cost would be

A public chat - like one that anyone can join at any time without needing an invitation? If so, then you really don't need any extra encryption. If not, then it depends on who's using your chat, how they use it, and for what purpose. Are the users of the chat room a small group with occasional users joining or leaving, or are many users expected to join and leave at any given moment? That being said, encrypting the n…

welp, I am just gonna look at Telegram/Signal source and make a lite version for it

Re: X's new "encrypted" XChat feature doesn't seem to be any more secure

#77
post #15

The implementation seems to be libsodium sealed boxes, with the key material sequestered using the juicebox.xyz protocol. In itself this seems broadly fine, with the significant proviso as mentioned in https://help.x.com/en/using-x/encrypted-direct-messages that identity is not verified at present, and as a result it's trivially MITMable. But there's something more subtle here. Juicebox means that your key material i…

[deleted]

Re: X's new "encrypted" XChat feature doesn't seem to be any more secure

#78

Earlier quoted context omitted.

Ah, the Zoom Gambit

wdym, elaborate

The first time zoom announced E2EE, they didn't actually have it and then said something like "well the server is the end, and then there is another end...". IIRC In the end they acquihired keybase so they fix the crypto for them.

Re: X's new "encrypted" XChat feature doesn't seem to be any more secure

#79
post #29

Earlier quoted context omitted.

It sounds like an offhand comment that we shouldn’t read much into. Bitcoin’s creator demonstrated an impressive mastery of cryptography—- it was made to be extremely resilient (including to quantum computing) and no one has ever broken it despite billions of dollars being on the line. Maybe Musk meant to say that he thinks his product will be similarly resilient. He might also mean that the secp256k1 elliptic curve…

The world's richest man was caught cheating at video games via hiring people to play for him for the sake of cred. I don't think I would give him anything.

You're right that he cheated (in some sense), but I don't think "caught" is the right word since he admitted it when he was asked point-blank. He paid someone to level up his character before he played it, not to stream in his name and pretend to be him.

Paying someone to level your character is officially against Blizzard's rules in all of their games, but their lack of enforcement reveals that they don't care as long as the monthly payments clear. World of Warcraft is overrun with people selling gold and boosts-- given that they're openly advertising this in Stormwind, it wouldn't be a stretch to call it de-facto legal (or at least decriminalized). Heck, Blizzard is selling gold and level boosts on its own website! [1]

[1] https://us.shop.battle.net/en-us/family/world-of-warcraft

Re: X's new "encrypted" XChat feature doesn't seem to be any more secure

#80
post #39
post #14

Earlier quoted context omitted.

Oh, wait, is Elon porting the venerable xchat to Rust? :)

> Oh, wait, is Elon porting the venerable xchat to Rust? :) If this hasn't been done already, I have a new weekend project!

For those of you who don't know, the project was archived in 2024 but there was at least one modern fork of XChat in the form of HexChat: https://hexchat.github.io/
Post reply on HN