Twitter rolls out encrypted DMs, but both sender and recipient must be verified users, no support for group messages, and message metadata is not encrypted
There are still some major limitations to the feature. — Twitter is beginning to roll out its long-promised encrypted direct messaging feature.
The launch also lands alongside incremental DM usability work, including threaded replies and expanded reactions. The contrast matters: the service is improving conversation mechanics while placing its most privacy-sensitive mode behind verification and excluding groups.
First-order effects
Only verified users can use the encrypted-DM option with one another; unverified accounts and group conversations remain on the ordinary messaging path.
Because metadata is not encrypted, the feature does not conceal the surrounding communication pattern even where message content receives added protection.
Second-order effects
Verification becomes a gate on a privacy feature, giving users who want protected one-to-one messaging an additional reason to qualify while limiting the feature’s usefulness for mixed-status social circles.
The lack of group support preserves a split product experience: users must choose between encrypted one-to-one exchanges and the broader functionality of standard DMs.
Third-order effects
The rollout illustrates how platforms can turn privacy features into differentiated account capabilities rather than universal communication infrastructure; whether that model persists depends on whether users accept the access constraint.
The trend: Private messaging is becoming a product-differentiation layer, but its value increasingly depends on interoperable features, broad access, and verifiable security guarantees.
Here are the caveats: -Sender and recipient have to be on the latest Twitter app. -Sender and recipient have to be subscribed to Twitter Blue or verified organizations. -The recipient has to follow the sender or have communicated with them before https://help.twitter.com/... http…
Twitter launched encrypted* DMs for verified accounts. * No sync * No group chats * No attachments * No timers * Vulnerable to MITM * No reporting (msg franking) * No Forward Secrecy * No Key Transparency * Private keys are NOT erased after web logout https://help.twitter.com/...
Super excited about launching Phase 1 of our Encrypted DM's project! Twitter seeks to be the most trusted platform on the internet, and encrypted Direct Messages are an important part of that. As Elon Musk said, when it comes to Direct Messages, the standard should be, if... http…
I appreciate Twitter makes it clear that there is *no protection from man-in-the-middle attacks. Plain-speak: not safe for anyone worried about privacy & safety to assume that this has equivalent protections to things like @signalapp. https://help.twitter.com/... https://twitter.…
Disappointing but unsurprising that Twitter's new encrypted DMs are a) only for twats paying for a tick and b) not actually terribly useful or secure. https://www.engadget.com/...
Also choosing to make security a subscription-only feature (where both parties have to pay), is interesting. It's Twitter's prerogative, but one would think adoption would come by making it free for the masses (esp when there are other options on the market).
According to their own docs, Twitter's encrypted DMs are not forward secure and do not protect against man-in-the-middle attacks. They launched something sub-par and less secure than ever major messenger. https://help.twitter.com/...
I'm confused by Twitter's claim that 1. your private key “never leaves the device and therefore is never communicated to Twitter” and 2. the claim that Twitter can apparently “compromise an encrypted conversation” if they so choose.
If Twitter can read your DMs “as a result of a compulsory legal process” then Twitter can read your DMs, period, and they're arguably not really meaningfully encrypted by today's standards. Maybe they'll implement e2e later but I don't see how this announcement amounts to much.
Twitter's encrypted DM feature is technically flawed, opt-in, limited to 1-to-1 text-based messages, restricted to a small user base, and generally inferior in just about every way to encrypted apps like Signal and WhatsApp. And all for just $8 a month. https://www.wired.com/...
https://help.twitter.com/... is refreshingly honest about how poor the Twitter encrypted DM implementation is. What it doesn't cover is how the existing design decisions make it *very* hard to implement some of what they want to add (like group DMs with any meaningful security)
I think it's good for any messaging platform to offer encryption. It certainly helps in my line of work. But I don't understand why you'd rush a product like this out and make people start using something that isn't as advertised (tho he's done it before with Tesla Autopilot).
Anyway for full disclosure I emailed @cstanley and the other Twitter people implementing encrypted DMs over a week ago to raise some (not super severe) concerns about the implementation and he never replied, so take any claims about external audits with appropriate salt
@samfbiddle Yes I am too. I mean I can think of ways they could do this, but implementing those ways would be a pretty ugly thing for an E2EE system to do.