The XChat lock icon has fine print
I went to X’s help page looking for one clean answer about encryption. I came away with three different message states.
An accepted Chat conversation can be end-to-end encrypted. A request sent to somebody who has not registered for Chat can be unencrypted. A message or image handed to Grok leaves the encrypted conversation so the model can read it. Those details all appear on X’s current Chat help page, but they are far more useful than the large word “encrypted” on a product screen.
The same page is unusually direct about another limit. X says Chat is not forward secure today. If a registered device’s private key is compromised, an attacker could decrypt the encrypted messages that device sent and received. X says it is working on key rotation for the future.
That honesty is welcome. It also changes the question I would ask before moving a sensitive conversation.
I would not ask, “Does XChat have encryption?” The answer is too broad to help. I would ask whether both people have registered for Chat, whether the lock is closed before the first message, whether either person plans to use Ask Grok, and what happens if a device key is exposed months later.
There is also a practical recovery tradeoff. X stores shares of the private key across three Juicebox realms, all currently operated by X. The PIN stays on the device, and two hardware-backed realms use HSMs. This makes multi-device recovery possible. It also means the design is doing more than keeping a key on one phone and hoping the owner never drops it in a river.
I keep an independent, plain-English version of these checks on the WexChat Pro safety page. It is not affiliated with X Corp. I update it because a lock icon can be accurate and still leave out the decision a normal person is trying to make.
For a casual group, these limits may be acceptable. For a lawyer, source, executive team, or anybody whose old messages would still matter after a device compromise, the footnotes are the product.
评论
发表评论