Smart Business Tips
Sign In
  • Home
  • Business
    • Business Coaching
    • Business Growth
    • Business Tools & Apps
  • Entrepreneurship
    • Entrepreneurs
    • Crypto
    • Innovation
    • Investing
    • Leadership
    • Productivity
  • Contact US
    • Blog
  • Branding
    • Content Marketing
    • Digital Marketing
    • E-commerce
    • Marketing Strategies
    • Personal Finance
  • Sales
    • Small Business Tips
    • Social Media
    • Startups
    • Tech Trends
    • Investing
  • Shop
Notification
OpenAI delays the release of its open model, again
Tech Trends

OpenAI delays the release of its open model, again

What’s Included in a Brand Identity Package?
Small Business Tips

What’s Included in a Brand Identity Package?

Why Your Company Updates Get Ignored — and How to Fix It
Entrepreneurship

Why Your Company Updates Get Ignored — and How to Fix It

Qi2 Wireless Charging: Everything You Need to Know (2025)
Tech Trends

Qi2 Wireless Charging: Everything You Need to Know (2025)

Font ResizerAa
Smart Business TipsSmart Business Tips
  • Home
  • Business
  • Entrepreneurship
  • Contact US
  • Branding
  • Sales
  • Shop
Search
  • Home
  • Business
    • Business Coaching
    • Business Growth
    • Business Tools & Apps
  • Entrepreneurship
    • Entrepreneurs
    • Crypto
    • Innovation
    • Investing
    • Leadership
    • Productivity
  • Contact US
    • Blog
  • Branding
    • Content Marketing
    • Digital Marketing
    • E-commerce
    • Marketing Strategies
    • Personal Finance
  • Sales
    • Small Business Tips
    • Social Media
    • Startups
    • Tech Trends
    • Investing
  • Shop
Sign In Sign In
Follow US
Made by ThemeRuby using the Foxiz theme. Powered by WordPress
Smart Business Tips > Blog > Tech Trends > Jack Dorsey says his ‘secure’ new Bitchat app has not been tested for security
Tech Trends

Jack Dorsey says his ‘secure’ new Bitchat app has not been tested for security

Admin45
Last updated: July 9, 2025 7:29 pm
By
Admin45
5 Min Read
Jack Dorsey says his ‘secure’ new Bitchat app has not been tested for security
SHARE


On Sunday, Block CEO and Twitter co-founder Jack Dorsey launched an open source chat app called Bitchat, promising to deliver “secure” and “private” messaging without a centralized infrastructure.

The app relies on Bluetooth and end-to-end encryption, unlike traditional messaging apps that rely on the internet. By being decentralized, Bitchat has potential for being a secure app in high-risk environments where the internet is monitored or inaccessible. According to Dorsey’s white paper detailing the app’s protocols and privacy mechanisms, Bitchat’s system design “prioritizes” security. 

But the claims that the app is secure, however, are already facing scrutiny by security researchers, given that the app and its code have not been reviewed or tested for security issues at all — by Dorsey’s own admission.

Since launching, Dorsey has added a warning to Bitchat’s GitHub page: “This software has not received external security review and may contain vulnerabilities and does not necessarily meet its stated security goals. Do not use it for production use, and do not rely on its security whatsoever until it has been reviewed.” 

This warning now also appears on Bitchat’s main GitHub project page, but was not there at the time the app debuted.

As of Wednesday, Dorsey added: “Work in progress,” next to the warning on GitHub. 

This latest disclaimer came after security researcher Alex Rodocea found that it’s possible to impersonate someone else and trick a person’s contacts into thinking they are talking to the legitimate contact, as the researcher explained in a blog post. 

Rodocea wrote that Bitchat has a “broken identity authentication/verification” system that allows an attacker to intercept someone’s “identity key” and “peer id pair” — essentially a digital handshake that is supposed to establish a trusted connection between two people using the app. Bitchat calls these “Favorite” contacts and marks them with a star icon. The goal of this feature is to allow two Bitchat users to interact, knowing that they are talking to the same person they talked to before. 

Dorsey did not respond to TechCrunch’s request for comment sent to his Block email address. 

A screenshot showing an example of a chat where an attacker has impersonated “Bob” in a chat with “Alice,” which Bitchat made it seem like it was really coming from Bob. (Image: Alex Rodocea)

On Monday, Radocea filed a ticket on the GitHub project to ask how to report the security flaw he discovered in the Bitchat Favorites system. Soon after, Dorsey marked it as “completed,” without comment. (Dorsey re-opened the ticket on Wednesday, saying security issues can be reported by posting on GitHub directly.)

Another person reported concerns with Dorsey’s claims that Bitchat has “forward secrecy,” a cryptographic technique that ensures that even if an attacker steals or compromises an encryption key, that attacker still cannot decrypt previously-sent messages.

Someone also pointed out a potential buffer overflow bug, which is a common type of security vulnerability where a hacker can force a device’s memory to spill out to other locations, opening the door for a data compromise.

Radocea warned that Bitchat users should not trust the app yet. 

“Security is a great feature to have for going viral. But a basic sanity check, like, do the identity keys actually do any cryptography, would be a very obvious thing to test when building something like this,” Radocea told TechCrunch. “There are people out there that would take the messaging around security literally and could rely on it for their safety, so the project in its current state could endanger them.”

Referring to his and other people’s findings, Radocea criticized Dorsey’s warning that Bitchat has not been tested for security. 

“I’d argue it has received external security review, and it’s not looking good,” he said.



Source link

Join Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
Share This Article
Facebook Email Copy Link
Leave a Comment Leave a Comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recipe Rating




Follow US

Find US on Social Medias
FacebookLike
XFollow
YoutubeSubscribe
TelegramFollow
Ad image

You Might Also Like

4 Best Folding Phones (2025), Tested and Reviewed
Tech Trends

4 Best Folding Phones (2025), Tested and Reviewed

By
Admin45
July 25, 2025
xAI says it has fixed Grok 4’s problematic responses
Tech Trends

xAI says it has fixed Grok 4’s problematic responses

By
Admin45
July 15, 2025
OnePlus Might Pose Risk to US Consumers
Tech Trends

OnePlus Might Pose Risk to US Consumers

By
Admin45
July 1, 2025
DOGE has built an AI tool to slash federal regulations
Tech Trends

DOGE has built an AI tool to slash federal regulations

By
Admin45
July 27, 2025
Verizon Rips Loyalty Discounts From Loyal Customers
Tech Trends

Verizon Rips Loyalty Discounts From Loyal Customers

By
Admin45
August 2, 2025
Learn how to raise a seed round from top VCs at Disrupt 2025
Tech Trends

Learn how to raise a seed round from top VCs at Disrupt 2025

By
Admin45
July 10, 2025

SmartBusinessTips

  • Business Tools & Apps
  • Marketing Strategies
  • Social Media
  • Tech Trends
  • Branding
  • Business
  • Crypto
  • Sales
  • About Us
  • Privacy Policy
  • Member Login
  • Contact Us
  • Business Coaching
  • Business Growth
  • Content Marketing
  • Branding

@Smartbusinesstips Copyright-2025-2027 Content.

Don't not sell my personal information
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?

Not a member? Sign Up