Close Menu
The Washington FeedThe Washington Feed

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Israeli strikes in Yemen kill 35 people, Houthis say

    September 11, 2025

    50 best Christmas gift ideas for moms in 2025, according to a mom

    September 11, 2025

    ‘Disagree Better’ governor is now pleading with Americans to stop hating each other

    September 11, 2025
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    The Washington FeedThe Washington Feed
    Subscribe
    • Home
    • World
    • US
    • seattle
    • Politics
    • Business
    • Tech
    • Contact Us
    The Washington FeedThe Washington Feed
    Home»Tech»Jack Dorsey says his ‘secure’ new Bitchat app has not been tested for security
    Tech

    Jack Dorsey says his ‘secure’ new Bitchat app has not been tested for security

    adminBy adminJuly 10, 2025No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    On Sunday, Block CEO and Twitter co-founder Jack Dorsey launched an open source chat app called Bitchat, promising to deliver “secure” and “private” messaging without a centralized infrastructure.

    The app relies on Bluetooth and end-to-end encryption, unlike traditional messaging apps that rely on the internet. By being decentralized, Bitchat has potential for being a secure app in high-risk environments where the internet is monitored or inaccessible. According to Dorsey’s white paper detailing the app’s protocols and privacy mechanisms, Bitchat’s system design “prioritizes” security. 

    But the claims that the app is secure, however, are already facing scrutiny by security researchers, given that the app and its code have not been reviewed or tested for security issues at all — by Dorsey’s own admission.

    Since launching, Dorsey has added a warning to Bitchat’s GitHub page: “This software has not received external security review and may contain vulnerabilities and does not necessarily meet its stated security goals. Do not use it for production use, and do not rely on its security whatsoever until it has been reviewed.” 

    This warning now also appears on Bitchat’s main GitHub project page but was not there at the time the app debuted.

    As of Wednesday, Dorsey added: “Work in progress,” next to the warning on GitHub. 

    This latest disclaimer came after security researcher Alex Radocea found that it’s possible to impersonate someone else and trick a person’s contacts into thinking they are talking to the legitimate contact, as the researcher explained in a blog post. 

    Radocea wrote that Bitchat has a “broken identity authentication/verification” system that allows an attacker to intercept someone’s “identity key” and “peer id pair” — essentially a digital handshake that is supposed to establish a trusted connection between two people using the app. Bitchat calls these “Favorite” contacts and marks them with a star icon. The goal of this feature is to allow two Bitchat users to interact, knowing that they are talking to the same person they talked to before. 

    Dorsey did not respond to TechCrunch’s request for comment sent to his Block email address. 

    A screenshot showing an example of a chat where an attacker has impersonated “Bob” in a chat with “Alice,” which Bitchat made it seem like it was really coming from Bob.Image Credits:Alex Radocea

    On Monday, Radocea filed a ticket on the GitHub project to ask how to report the security flaw he discovered in the Bitchat Favorites system. Soon after, Dorsey marked it as “completed,” without comment. (Dorsey reopened the ticket on Wednesday, saying security issues can be reported by posting on GitHub directly.)

    Another person reported concerns with Dorsey’s claims that Bitchat has “forward secrecy,” a cryptographic technique that ensures that even if an attacker steals or compromises an encryption key, that attacker still cannot decrypt previously sent messages.

    Someone also pointed out a potential buffer overflow bug, which is a common type of security vulnerability where a hacker can force a device’s memory to spill out to other locations, opening the door for a data compromise.

    Radocea warned that Bitchat users should not trust the app yet. 

    “Security is a great feature to have for going viral. But a basic sanity check, like, do the identity keys actually do any cryptography, would be a very obvious thing to test when building something like this,” Radocea told TechCrunch. “There are people out there that would take the messaging around security literally and could rely on it for their safety, so the project in its current state could endanger them.”

    Referring to his and other people’s findings, Radocea criticized Dorsey’s warning that Bitchat has not been tested for security. 

    “I’d argue it has received external security review, and it’s not looking good,” he said.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    admin
    • Website

    Related Posts

    How Bill Gates’s fellowship program is adapting to global uncertainty

    September 11, 2025

    Children hacking their own schools for ‘fun’, watchdog warns

    September 11, 2025

    Learn what makes a pitch land at Disrupt 2025

    September 11, 2025
    Leave A Reply Cancel Reply

    Demo
    Our Picks
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Don't Miss

    Israeli strikes in Yemen kill 35 people, Houthis say

    World September 11, 2025

    At least 35 people were killed in Israeli air strikes on Houthi-controlled areas of Yemen…

    50 best Christmas gift ideas for moms in 2025, according to a mom

    September 11, 2025

    ‘Disagree Better’ governor is now pleading with Americans to stop hating each other

    September 11, 2025

    August CPI: Inflation remained elevated ahead of Fed rate cut decision

    September 11, 2025

    Subscribe to Updates

    Get the latest creative news from SmartMag about art & design.

    About Us

    At TheWashingtonFeed.com, we are committed to delivering accurate, timely, and relevant news from around the world. Whether it’s breaking developments in U.S. politics, major international affairs, or the latest trends in technology, our mission is to keep our readers informed with fact-driven journalism and insightful analysis.

    Email Us: Confordev@gmail.com

    Our Picks

    Israeli strikes in Yemen kill 35 people, Houthis say

    September 11, 2025

    France suspects foreign intelligence over pigs heads left outside mosques

    September 11, 2025

    Ireland threatens to withdraw from Eurovision if Israel participates

    September 11, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Contact Us
    • About Us
    • Privacy Policy
    • Terms and Condition
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.