Simon Fell

@superfell.bsky.social

https://github.com/superfell https://hachyderm.io/@superfell

So yesterday on X someone from X engineering tweeted at me that X does, in fact, use HSMs and the key ceremonies are “coming soon.” I’ve updated the post but I’ll be honest this whole thing doesn’t fill me with good feelings.

If your DMs are “encrypted” but one org holds all the keys, you haven’t distributed trust – you’ve built a backdoor. Juicebox only works when boundaries are real. Separation isn’t optional. Replication != distribution.

Don’t Put All Your Juice in One Box

At Juicebox, we believe key recovery should be secure, user friendly, and actually… work. That means it has to be more than cryptographic theater. It has to reflect the real world, where systems get h...

juicebox.xyz