Saturday, August 15, 2026
HomeTechnologyJack Dorsey says his 'secure' new Bitchat app has not been tested...

Jack Dorsey says his ‘secure’ new Bitchat app has not been tested for security


On Sunday, Block CEO and Twitter co-founder Jack Dorsey launched an open source chat app called Bitchat, promising to deliver โ€œsecureโ€ and โ€œprivateโ€ messaging without a centralized infrastructure.

The app relies on Bluetooth and end-to-end encryption, unlike traditional messaging apps that rely on the internet. By being decentralized, Bitchat has potential for being a secure app in high-risk environments where the internet is monitored or inaccessible. According to Dorseyโ€™s white paper detailing the appโ€™s protocols and privacy mechanisms, Bitchatโ€™s system design โ€œprioritizesโ€ security.ย 

But the claims that the app is secure, however, are already facing scrutiny by security researchers, given that the app and its code have not been reviewed or tested for security issues at all โ€” by Dorseyโ€™s own admission.

Since launching, Dorsey has added a warning to Bitchatโ€™s GitHub page: โ€œThis software has not received external security review and may contain vulnerabilities and does not necessarily meet its stated security goals. Do not use it for production use, and do not rely on its security whatsoever until it has been reviewed.โ€ย 

This warning now also appears on Bitchatโ€™s main GitHub project page, but was not there at the time the app debuted.

As of Wednesday, Dorsey added: โ€œWork in progress,โ€ next to the warning on GitHub.ย 

This latest disclaimer came after security researcher Alex Rodocea found that itโ€™s possible to impersonate someone else and trick a personโ€™s contacts into thinking they are talking to the legitimate contact, as the researcher explained in a blog post.ย 

Rodocea wrote that Bitchat has a โ€œbroken identity authentication/verificationโ€ system that allows an attacker to intercept someoneโ€™s โ€œidentity keyโ€ and โ€œpeer id pairโ€ โ€” essentially a digital handshake that is supposed to establish a trusted connection between two people using the app. Bitchat calls these โ€œFavoriteโ€ contacts and marks them with a star icon. The goal of this feature is to allow two Bitchat users to interact, knowing that they are talking to the same person they talked to before.ย 

Dorsey did not respond to TechCrunchโ€™s request for comment sent to his Block email address.ย 

A screenshot showing an example of a chat where an attacker has impersonated โ€œBobโ€ in a chat with โ€œAlice,โ€ which Bitchat made it seem like it was really coming from Bob. (Image: Alex Rodocea)

On Monday, Radocea filed a ticket on the GitHub project to ask how to report the security flaw he discovered in the Bitchat Favorites system. Soon after, Dorsey marked it as โ€œcompleted,โ€ without comment. (Dorsey re-opened the ticket on Wednesday, saying security issues can be reported by posting on GitHub directly.)

Another person reported concerns with Dorseyโ€™s claims that Bitchat has โ€œforward secrecy,โ€ a cryptographic technique that ensures that even if an attacker steals or compromises an encryption key, that attacker still cannot decrypt previously-sent messages.

Someone also pointed out a potential buffer overflow bug, which is a common type of security vulnerability where a hacker can force a deviceโ€™s memory to spill out to other locations, opening the door for a data compromise.

Radocea warned that Bitchat users should not trust the app yet.ย 

โ€œSecurity is a great feature to have for going viral. But a basic sanity check, like, do the identity keys actually do any cryptography, would be a very obvious thing to test when building something like this,โ€ Radocea told TechCrunch. โ€œThere are people out there that would take the messaging around security literally and could rely on it for their safety, so the project in its current state could endanger them.โ€

Referring to his and other peopleโ€™s findings, Radocea criticized Dorseyโ€™s warning that Bitchat has not been tested for security.ย 

โ€œIโ€™d argue it has received external security review, and itโ€™s not looking good,โ€ he said.



Source link

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular

Recent Comments

Translate ยป