Twitter rolls out encrypted DMs, but both sender and recipient must be Blue subscribers, group messages are not supported, and message metadata is not encrypted
Starting with Verified Users Jay Peters / The Verge : Twitter launches encrypted DMs behind a paywall Geoff Desreumaux / WeRSM : Twitter Launches Encrypted DMs, But Only For Paid Subscribers Tweets: Elon Musk / @elonmusk : Early version of encrypted direct messages just launched. Try it, but don't trust it yet. Paul Miller / @paulmillr : Twitter launched encrypted* DMs for verified accounts. * No sync * No group chats * No attachments * No timers * Vulnerable to MITM * No reporting (msg franking) * No Forward Secrecy * No Key Transparency * Private keys are NOT erased after web logout https://help.twitter.com/... John Scott-Railton / @jsrailton : I appreciate Twitter makes it clear that there is *no protection from man-in-the-middle attacks. Plain-speak: not safe for anyone worried about privacy & safety to assume that this has equivalent protections to things like @signalapp. https://help.twitter.com/... https://twitter.com/... John Scalzi / @scalzi : Twitter is too far down the trust thermocline for me to entrust any sensitive information to it at this point, and certainly not for $8 a month, especially when there are other end-to-end encryption options for free. https://www.theverge.com/... Harry McCracken / @harrymccracken : End-to-end encryption is hard. https://www.engadget.com/... @evan_greer : I'm not angry (or surprised) I'm just disappointed https://www.wired.com/... Ryan Mac / @rmac18 : Here are the caveats: -Sender and recipient have to be on the latest Twitter app. -Sender and recipient have to be subscribed to Twitter Blue or verified organizations. -The recipient has to follow the sender or have communicated with them before https://help.twitter.com/... https://twitter.com/... Kate Bevan / @katebevan : Disappointing but unsurprising that Twitter's new encrypted DMs are a) only for twats paying for a tick and b) not actually terribly useful or secure. https://www.engadget.com/... Christopher Stanley / @cstanley : Super excited about launching Phase 1 of our Encrypted DM's project! Twitter seeks to be the most trusted platform on the internet, and encrypted Direct Messages are an important part of that. As Elon Musk said, when it comes to Direct Messages, the standard should be, if... https://twitter.com/... Matthew Garrett / @mjg59 : https://help.twitter.com/... is refreshingly honest about how poor the Twitter encrypted DM implementation is. What it doesn't cover is how the existing design decisions make it *very* hard to implement some of what they want to add (like group DMs with any meaningful security) Andy Greenberg / @a_greenberg : Twitter's encrypted DM feature is technically flawed, opt-in, limited to 1-to-1 text-based messages, restricted to a small user base, and generally inferior in just about every way to encrypted apps like Signal and WhatsApp. And all for just $8 a month. https://www.wired.com/... Steve Weis / @sweis : According to their own docs, Twitter's encrypted DMs are not forward secure and do not protect against man-in-the-middle attacks. They launched something sub-par and less secure than ever major messenger. https://help.twitter.com/... Matthew Garrett / @mjg59 : Anyway for full disclosure I emailed @cstanley and the other Twitter people implementing encrypted DMs over a week ago to raise some (not super severe) concerns about the implementation and he never replied, so take any claims about external audits with appropriate salt Sam Biddle / @samfbiddle : If Twitter can read your DMs “as a result of a compulsory legal process” then Twitter can read your DMs, period, and they're arguably not really meaningfully encrypted by today's standards. Maybe they'll implement e2e later but I don't see how this announcement amounts to much. Kate Conger / @kateconger : I am very excited for Twitter to move toward encrypted DMs but it doesn't sound like that's what we have today https://twitter.com/... @rmac18 : Also choosing to make security a subscription-only feature (where both parties have to pay), is interesting. It's Twitter's prerogative, but one would think adoption would come by making it free for the masses (esp when there are other options on the market). @rmac18 : I think it's good for any messaging platform to offer encryption. It certainly helps in my line of work. But I don't understand why you'd rush a product like this out and make people start using something that isn't as advertised (tho he's done it before with Tesla Autopilot). Sam Biddle / @samfbiddle : I'm confused by Twitter's claim that 1. your private key “never leaves the device and therefore is never communicated to Twitter” and 2. the claim that Twitter can apparently “compromise an encrypted conversation” if they so choose. Matthew Green / @matthew_d_green : @samfbiddle Seems like they just mean they could substitute keys to do an MITM attack which isn't surprising, but what a weird way to say it. Matthew Green / @matthew_d_green : @samfbiddle Yes I am too. I mean I can think of ways they could do this, but implementing those ways would be a pretty ugly thing for an E2EE system to do.
Context & Ripple Effects
Twitter is attaching a private-communications feature to its paid verification tier rather than offering it as a default capability. That contrasts with WhatsApp's earlier default rollout of end-to-end encryption across communications, setting a clear usability and access benchmark.
The launch also sits in a credibility-sensitive arc: related coverage quickly found that Twitter's design did not provide end-to-end encryption against man-in-the-middle attacks. The gap between the label and the implementation matters as much as the subscriber restriction.
First-order effects
- Blue subscribers and verified organizations can use the feature only when the other participant also qualifies, sharply limiting the immediately reachable pool for private conversations.
- Users needing group chats, attachments, message timers, or protected metadata must keep using other channels; the feature does not replace a general-purpose secure messenger.
Second-order effects
- The two-sided subscription requirement weakens network effects: a user cannot gain the feature's value unilaterally, making paid conversion harder to justify for conversations with non-subscribers.
- Established encrypted messaging services retain a practical advantage where privacy features work by default and across groups, while Twitter faces greater scrutiny over what its encryption claim covers.
Third-order effects
- If platforms continue gating privacy features behind paid tiers, private communication may become fragmented by subscription status rather than determined solely by a service's user base.
- This episode points to a durable trust test for social platforms: security labels will increasingly be judged against implementation details such as metadata exposure, key management, and group support—not marketing language alone.
The trend: Social platforms are testing subscription monetization around safety and privacy features, but technical assurance and broad interoperability determine whether those features create lasting value.