- Hey y’all. Reminder not to trust a platform owned and operated by a Nazi manchild. 
- TL;dr of the article : - They keep your private key on their servers.
- Their implementation allows for AITM attacks.
- It’s closed source.
- There’s no perfect forward secrecy.
 - This secret stays between you, me, and Elon. - I hope politicians use the hell out of it, so we can see what they really think when it gets (inevitably) hacked in a few weeks. - What is the “A” in “AITM”? - This is the first time I heard of AITM, thought it was a new name for MITM: - Are you sure that site is trustworthy? It kinda reads like an LLM being told to explain the difference between two names for the same thing and basically rephrasing the same thing. I’d imagine it might just be a different name to get rid of a male-coded word. 
 
- Adversary 
- It’s just MITM but with extra steps - Ah yes, Malcolm in the Middle is behind this all along. 
 
- Agencies 
- Anal 
- Asshole 
- Aliens 
- Elon. 
- Anyone 
- Administrator 
 
- is it different with signal, telegram, whatsapp? 
- If you chat on Xitter you‘re chatting with mecha Hitler. 
- They are stupid, but not that stupid. - Never attribute to malice what can be attributed to incompetence. - I used to give the benefit of the doubt but when there are bad incentives in play and shit keeps happening… then perhaps that is naïve sometimes, unfortunately. - Do you mean bad incentives? - And sure, I don’t disagree, but these people are also not actually that smart. I would worry more about this getting hacked in a week way before Elon gets a chance to use it against anyone. - Thanks, I do. 
 
 
 
 
 
- Shouldn’t trust it yet. - Or ever. 
- offering me end-to-end encrypted chat - No one - not even X - can access or read your messages - This key is then stored on X’s servers - So…they’re just blatantly lying? - It’s encrypted with a 4 digit pin so they’ll have to spend at least 316.8809e-10 years on brute-forcing it. - That’s why my PIN is 5 digits: 12345 - One. Two. Three. Four. Five? - That’s amazing. I’ve got the same combination on my luggage. - Suck. Suck. Suck. Suck! 
 
 
 
- The Muskrat lying? No, never! 
 
- I hope Elon musk gets cancelled(cancer) for this useless nonsensical black box 
- “xchat” sounds like one of those porn chat rooms 
- XChat, has some red flags. - With a white circle and a swastika inside? 
- If you trust ANYTHING Musk has for you well then have I got a bridge to sell you. 
- probably??? try definitely and ever 
- …yet? How bout just not trusting it at all? - Hah, beat me by 17 seconds! 
 
- Brain damaged people trust x again. 
- Yet? More like never. 
- YET? 
- That “yet” is the narrative hook to trick us into feeling like it will soon be trustworthy, and that our assumed suspicions refer to a temporary state of untrustworthiness. Clever girls! - Feels like Bluesky’s federation promise. - I think you can install your own bluseky instance and federated with others. - I don’t consider the PDS stuff to be fully federated. That’s just keeping your data on a different server, as far as I understand it. To be federated it needs to be a full interoperable server like mastodon, or lemmy. - You should also be able to host a non federated instance, or one with limited federation. - If they have moved past that, and I can open a server and have people sign up for accounts, then I stand corrected. - Bluesky federates across different layers, it’s modular, it doesn’t have a comparable same-layer federation. It is fully interoperable, just not by the method you’re used to. - You can host your own partial appview now (caching and indexing your and your friends’ comment), and multiple people have managed to run their own relays for cheap (caching most of the posts in the network), and you can pull the rest of data you need to browse from the other relays and use the service as usual. You can run your own moderation labeler, use your own app, just your own account, etc… - Just look at the interoperable blacksky project by a bunch of black devs making their own infrastructure for accounts and moderation, etc. - To be non federated, all you have to do is not announce your server and not accept arbitrary connections - Due to content addressing, limited federation isn’t really a thing by the usual definition. You can filter content from any PDS you don’t like, but can’t really control who can see already public posts 
 
 
 
- Correct, foolish human! Now sign up. 
 
- shouldn’t trust it yetshouldn’t trust it ever



















