NEWS

X Rolls Out Enhanced DM Encryption

X unveils enhanced DM encryption for premium users on iOS, a move towards its “everything app” future. Despite robust cryptography, a four-digit PIN and unencrypted metadata reveal a balance between security and user convenience.

By
LNGFRM Team
Published June 4, 2025
"Stylized white X on a dark, scratched background."
Image courtesy of Socialmediatoday

In the ever-evolving digital landscape, where privacy is a currency often devalued, X has thrown its hat into the ring once more, rolling out an updated direct message encryption system for its Premium users.

This move, framed as a significant leap forward, arrives on the heels of the platform’s new “XChat” messaging experience, promising a more secure haven for digital conversations.

Yet, as with many ambitious technological endeavors, the devil, or perhaps the digital ghost, lies in the details.

The narrative of X’s encryption journey has been a winding one.

It’s not so long ago that Elon Musk himself, ever the blunt diagnostician, labelled X’s previous attempts at message encryption as “clunky” and functionally inadequate for one-to-one exchanges.

While audio and video call encryption, implemented post-Musk acquisition, reportedly worked without a hitch, the path to fully encrypted DMs demanded a monumental overhaul of X’s back-end messaging infrastructure.

That overhaul, X now claims, is complete, with the ultimate goal of making encrypted DMs the default for all users.

This is, undeniably, a substantial undertaking, signaling a commitment to a feature that is increasingly expected in modern communication platforms.

At the heart of this updated system lies a familiar cryptographic dance.

Upon entering Chat for the first time, each user generates a unique private-public key pair.

The private key, the digital master key to your conversations, is then securely stored on X’s infrastructure, protected by a user-defined PIN.

This PIN, crucially, never leaves the device, acting as a local gatekeeper.

Beyond these personal keys, a per-conversation key is generated, responsible for encrypting the actual message content.

The private-public keys then orchestrate the secure exchange of these conversation keys between participants.

On paper, it’s a standard, robust framework.

However, a closer look at the implementation reveals a fascinating tension between security and user convenience.

The PIN, the lynchpin of private key recovery, is a mere four digits. In an era where biometrics, multi-factor authentication, and complex alphanumeric passphrases are the norm for securing sensitive data, a four-digit PIN feels curiously anachronistic.

It’s a design choice that prioritizes ease of use, perhaps to encourage adoption, but it undoubtedly introduces a potential weak point.

While X assures users of “strong cryptographic schemes” encrypting every message, link, and reaction before it leaves the sender’s device and while stored on X’s infrastructure, the relative simplicity of the PIN serves as a stark reminder that even the most formidable digital fortresses can have a deceptively simple back door.

The rollout itself is also subject to practical limitations.

For now, this enhanced security blanket extends primarily to Premium subscribers and, more specifically, to those using the latest X app on iOS.

Android and web users remain in the unencrypted waiting room, a significant caveat for a platform striving for universal utility.

Furthermore, a secure connection isn’t just a matter of having the right app; it requires an established relationship: the recipient must follow the sender, have previously accepted a DM, or initiated a message.

This thoughtful prerequisite aims to prevent unsolicited encrypted messages, ensuring a degree of mutual interest before the secure channel is activated.

Beyond the technicalities, the true measure of privacy often lies in what remains unencrypted.

X’s updated documentation makes a critical distinction: while message content, including links, media, and reactions, is indeed encrypted, associated metadata – such as the recipient and creation time – is not. This is a crucial point often overlooked by users.

It means that while the “what” of your conversation is hidden, the “who,” “when,” and “with whom” can still be observed.

For those engaged in sensitive communications, this unencrypted metadata represents a significant digital shadow, a breadcrumb trail that could potentially be used for surveillance or analysis.

Similarly, any shared posts within an encrypted chat, while their content remains encrypted, will still leave a record on X’s servers that they were shared.

It’s a reminder that “encrypted” doesn’t always equate to “anonymous” or “untraceable.”

Then there’s the intriguing behavior upon logging out.

X states that logging out from your account will automatically delete all messages, including encrypted DMs, from that specific device.

Private keys and conversation keys are also erased.

While the system allows for re-fetching and decrypting conversations upon logging back in, using the private key previously accessible, this auto-deletion feature could lead to unexpected user experiences.

Imagine logging out briefly on a public device and then realizing your local message history has vanished, only to reappear upon re-login.

It’s a security measure, perhaps, but one that could feel disruptive to the average user accustomed to persistent chat histories.

Ultimately, X’s updated encryption is a step in the right direction, particularly given its past struggles.

It provides a more secure option for Premium users, with the promise of broader availability.

But the motivations behind this push extend beyond mere privacy.

X openly acknowledges that it hopes this “added assurance will also eventually lead to more people transferring money in the app, once X Payments come around.” This reveals the larger ambition: to transform X into an “everything app,” a financial hub where trust in security is paramount.

The question then becomes, does a system with a four-digit PIN and unencrypted metadata truly foster the profound level of trust required for financial transactions?

X’s commitment to open-sourcing its encryption system information later this year is commendable, offering a degree of transparency that could build confidence.

Yet, the current iteration presents a fascinating paradox: a significant technical overhaul yielding a system that is both a leap forward and, in certain aspects, a cautious compromise.

It’s a testament to the complex balancing act between absolute security, user convenience, and the vast, ambitious vision of a platform striving to be indispensable in every facet of our digital lives.

Whether this blend of robust cryptography and convenient vulnerabilities will be enough to win over a privacy-conscious user base remains to be seen.

Author

  • LNGFRM Team

    Frank DiBernardo handles LNGFRM's Foodie and Miscellaneous writing tasks. He's always getting ideas from users, so don't be afraid to send an email to the editor.

Daily Newsletter
Subscribe to our Newletter!
You May Also Like
© 2026 LNGFRM. All rights reserved.