• FreedomAdvocate@lemmy.net.au
    link
    fedilink
    English
    arrow-up
    7
    ·
    21 hours ago

    No - did you even read the article? An x employee confirmed that they’re using the “special” servers to store the keys that mean that they cannot see them. The author then says that the employee confirming it doesn’t mean they do, because the author doesn’t want it to be true.

    • Natanael@infosec.pub
      link
      fedilink
      English
      arrow-up
      1
      ·
      edit-2
      5 hours ago

      There are hardware for that called hardware security modules, but yeah I definitely wouldn’t trust Twitter’s implementation - especially because they probably just need the auth team to tell the HSM that the user logged in when they didn’t to get that key

      A proper implementation would use multiple security measures and require a reset (delete) of certain private account data before the account access can be reset, otherwise the user’s password would be needed (for key derivation) or some other secret held by the user’s devices (in the TPM chip or equivalent)