The issue is everything this tweet conveniently omits: metadata.
WhatsApp’s own privacy policy states they collect “time, frequency, and duration of your activities and interactions,” device info, IP address, phone number, and your contact graph.
Cloud backups to Google Drive or iCloud require manual opt-in for E2E encryption.
Meta AI interactions aren’t E2E encrypted at all.
The client is closed source, so you’re trusting Meta’s attestation that implementation matches their whitepaper.
In 2024, Meta complied with 78% of US law enforcement requests for WhatsApp data. Last month, University of Vienna researchers exploited the Contact Discovery API to harvest metadata on 3.5 billion accounts.
Former NSA and CIA Director Michael Hayden: “We kill people based on metadata.”
Elon is right that WhatsApp has serious privacy concerns. Meta’s business model is surveillance capitalism, and their privacy policy explicitly allows cross-platform data sharing for advertising.
But recommending 𝕏 Chat over Signal inverts the actual security hierarchy. This isn’t opinion. It’s now documented by X’s own auditors.
In June 2025, 𝕏 engaged @trailofbits to audit XChat. The report, made public in October 2025, is damning.
Executive summary: “The XChat protocol and implementation has multiple serious security vulnerabilities that need to be addressed immediately.”
Trail of Bits’ recommendation: “Consider temporarily pausing the XChat feature to prioritize addressing the identified security concerns.”
The audit found 6 vulnerabilities, 3 rated High severity, 1 Medium:
1. Server can select the conversation key for all participants. Signatures are optional and not validated when present. This allows a malicious server to intercept all messages.
2. Server can inject its own public keys for any user, enabling person-in-the-middle attacks at will.
3. If a user suspects compromise and requests a key reset, the server can ignore the request and continue providing the old compromised key.
4. An attacker can send a single ciphertext that decrypts to different plaintexts for different recipients. Trail of Bits notes this could be used to manipulate cryptocurrency trades by sending “buy” to some users and “sell” to others.
Many of these issues “directly correspond to design flaws discovered during Trail of Bits’ Direct Messaging design analysis in 2023.” X was warned about these architectural problems two years before launching XChat. They shipped anyway.
Safety Numbers Are Broken
X implemented safety numbers after criticism, but Trail of Bits found the implementation “does not actually offer any security.” The algorithm only uses one user’s public key in the calculation. Safety numbers that don’t incorporate both parties’ keys cannot detect key substitution attacks.
Of the 6 findings: 3 Resolved, 2 Unresolved, 1 Undetermined.
XChat stores user private keys on X’s servers using the Juicebox protocol, protected by a 4-6 digit PIN. Juicebox is designed to split trust across independent parties or use Hardware Security Modules that even the operator cannot bypass.
X does neither.
Professor @matthew_d_green analyzed X’s deployment and found all Juicebox realms appear to be software-only and under X’s control. Nora Trapp, Juicebox’s protocol designer, performed timing analysis confirming this and explicitly warned against single-provider deployments: “If a single subpoena, exploit, or admin mistake compromises all your realms at once, they’re not independent realms, they’re aliases.”
A 4-digit PIN has 10,000 combinations. Without hardware-enforced rate limiting, that’s brute-forceable in seconds. X controls the rate limiting.
No Forward Secrecy
X’s own documentation confirms that compromising a device key exposes the user’s entire message history. Signal solved this with Double Ratchet in 2013. Every message generates new keys. XChat is architecturally behind by over a decade.
I use 𝕏 daily. I work in security. I’m not posting this to attack the platform. I’m posting this because security claims require evidence, and the evidence here is clear.
wait lex fridman out here doing these insane 3+ hour podcasts on WINDOWS??
no macbook, no apple glow, just straight beast mode setup
dude's interviewing legends without the overpriced fruit
respect.
Walls, buildings, hills. All these affect how much Bluetooth signal travels from one person's phone to another. In the simulation, the physical environment modulates the Bluetooth strength.
Here you can see how the signal rather travels around the wall than passing through it.
bitchat now has:
- photos/audio notes in bluetooth mesh
- better routing algorithm for stabler and longer range meshes
- uses @torproject's arti framework for speed and reliability
- audited by 3rd party security group and addressed all findings
https://t.co/tAm0IN7VD7
🚨 Hansi Flick on Kylian Mbappé and the Barça high-line:
Hansi Flick: "You might have to help me. How many Clásicos have we played and lost in the past year and a half? Do you know?"
Reporter: "You lost one."
Hansi Flick: "We lost one, okay. That's what it's about. I know that Mbappé is a great player, and for him, with spaces behind the last line, he's really exceptional."
"But for us too, it's about competing against one of the best teams in the world. We'll adapt some things as we always do, but it's not specifically about Mbappé."
"It's about Real Madrid, and it's about how we want to play, and our expectations for what they want to do."
"The situation is always like this, but we focus on our philosophy and our idea of how to play. We want to play like Barça."
@WriterVijaysb Dear Sir/madam
@BlrCityPolice@CybercrimeCID@DgpKarnataka
Please confirm above case is valid or not
@WriterVijaysb presenting him as Bengaluru Cyber crime police officer and doing unconstitutional behaviours in X community by commenting unconstitutional words to some accounts
BREAKING: Malo Gusto caught tampering with the penalty spot during VAR review in Chelsea vs Fulham. Nonchalant shithousery while referee checks the monitor... spotted by the cameras! ⚽🕳️
Gamesmanship or cheating? FA to investigate? 🚨