top | item 35754512

(no title)

directionless | 2 years ago

Are there details about how key management works? Where are the keys stored, what has access to them, etc? Because this tweet is empty hype.

discuss

order

danenania|2 years ago

The fact that it will be implemented in a web app makes it security theater from the start. It doesn’t matter how key management works.

If someone with access to Twitter’s servers wants to read DMs, they will now need to include an extra snippet of JS in the frontend response of the user they’re targeting for a single request. It’s (maybe) a bit harder than getting the message right from the DB, but still not much of an obstacle for a motivated insider.

H8crilA|2 years ago

Don't worry, it's strong military grade crypto, uses AES-256 /s