X Money Is Facing Security Concerns: Are We Making Tech Too Convenient To Be Secure?

X Money has barely become widely available before X users have started reporting something that’s as creepy as it is concerning. That is, those all-too familiar password reset emails they never requested.

According to Crypto News, product engineering team member Mridul Singhai announced on 1 September that X was investigating reports of odd password reset request emails, with the company saying attackers appeared to be trying to gain unauthorised access to accounts. Most importantly, however, despite some users reportedly received multiple emails in a short period, X has maintained confience in the fact that they have found no evidence of a breach so far.

So we’re not starting a conversation about X Money being hacked, because, for all intents and purposes, that hasn’t actually happened yet (although a clear attempt was made). Rather, what I’d prefer to focus on is the obvious concern users are having about the so-called “everything app” and its potential vulnerabilities.

X Money is a major part of Elon Musk’s ambition to turn X into an “everything app”. The idea is supposed to be that X will become a single platform where users can communicate with each other, shop online, make payments and eventually, manage more and more aspects of their digital lives. It’s likely that this will include things like managing smart home management systems, making bookings (whether for flights, restaurants or whatever else) and so much more.

And so, naturally, the biggest issue and question that is rising to the surface of the whole Musk, X and social media frenzy is whether we may be unintentionally making technology so convenient that we’re simultaneously making it less secure. In some ways, the idea is that our endeavour to remove as much friction from our lives as possible may be leading to us making it easier than ever for bad actors to do dangerous things. That is, we’re putting everything in one place and consolidating all our information into a single goldmine. So surely, that will create the biggest possible target for nefarious individuals and groups who will now have a direct road map to access everything about you, all at once?

 

The Appeal of the “Everything App”

 

The idea is straightforward: we already use countless apps every day for messaging, social media, shopping, payments, banking and entertainment. So much so, in fact, that it’s getting hard to keep up. So, when we think of it like that, in many ways, an everything app sounds like the best possible solution: a promise to bring many of these functions together and just make life easier. 

X Money is one of many steps that Musk is taking towards realising that vision. The service allows users to hold deposits, send peer-to-peer payments, pay bills, transfer money and send cheques without leaving X at all.

I don’t think it takes much imagination to figure out why this would be appealing. We’re talking about fewer apps, fewer logins, fewer passwords and just so much less jumping between different services. One would also assume that this would mean users would have a single app that understands their history, habits and preferences, which would also be incredibly useful in the pursuit of having digital “services” (so to speak) that can be properly personalied.

But the issue is that while there certainly are countless benefits we can imagine in this potential, there are obvious concerns that seem likely to become increasingly worrying as more and more functionality is added.

After all, the more valuable an account becomes, the more attractive it potentially becomes to attackers. And that leaves us all in a little bit of a predicament.

 

 

From a Social Media Account To Financial Identity

 

If someone gains access to an ordinary social media account, there are already some very serious immediate consequences. They might impersonate the user, send messages, access private information or use the account to target their followers – something we all know happens more regularly than we’d like to imagine possible. In fact, just this morning, a friend was telling me about another mutual friend of ours had her Whatsapp account hacked, with the hackers attempting to get money out ouf her friends and family. And these days, this is just such a familiar story, it’s barely worth talking about anymore, which is quite shocking in itself.

But now, if we add financial services to that same identity, the stakes become a whole lot higher, and naturally, our levels of concern increase too.

And circling back to X Money, this doesn’t mean that the current password-reset activity has resulted in financial accounts being compromised. Just to be clear, there really is no evidence that X Money itself has been breached or that the current incident has resulted in widespread account takeovers.

But the point is that it’s made us really start thinking about what happens as X continues adding functionality. If your X account eventually becomes your social media profile, messaging account, shopping account and payment account, it becomes considerably more valuable than any one of those accounts would be on its own.

In cybersecurity terms, you’re potentially creating a much larger single point of failure.

 

Convenience Isn’t Necessarily Good for Security

 

This isn’t a problem unique to X, although X is kind of becoming a main character in the discussion.

Much of modern technology is built around removing friction – we can sign into services with existing accounts, save payment details, connect apps and automate tasks. It’s super convenient because we don’t have to think about every individual system, but security often works in the opposite direction.

Separating systems and accounts can limit the damage when one is compromised. Additional authentication steps can make it harder for someone else to gain access (hell, it makes it hard for you to access your own darn account). Indeed, having different passwords means one stolen credential doesn’t automatically unlock everything else, and that not only makes things more secure but it also makes us feel a little better.

In other words, security often benefits from compartmentalisation, while convenience benefits from consolidation.

But the issue is, the “everything-app” concept is essentially built around consolidation. Now, that doesn’t make it inherently insecure, because a single platform can, in theory, have extremely strong security measures.

However, the consequences of a successful attack could potentially be much greater. So, is the convenience and time saved by having everything in one place really worth serious security vulnerabilities?

 

The Password-Reset Incident Feels Like a Warning

 

There’s another reason the current X situation is worth paying attention to (and perhaps the reason why the news gave us all a weird little gut feeling).

According to reporting on the incident, X’s password recovery system can be triggered using a public username, meaning someone doesn’t necessarily need access to a user’s email account or anything private or specific to initiate a reset request. X also offers Password Reset Protection, which adds additional verification to the process.

That doesn’t mean these emails prove that attackers have someone’s credentials. In fact, they’re more likely to just be part of a phishing scheme, an attempt to disrupt users or a broader effort to gain access to accounts. At this stage, there are several possible explanations and it would be premature to claim we know exactly what’s happening.

What is significant, however, is that X itself has linked the apparent targeting to the increased availability of X Money, and that seems to suggest that something has changed in the perceived value of an X account. And it seems like this has happened recently.

It used to be a place for discussion (back when it was Twitter), but it’s no longer necessarily just a place where someone posts. Now, it could become a gateway to money and so much more. I still find that to be quite a weird concept, if I’m perfectly honest, and I don’t think I’m the only one.

 

What happens when everything has one login?

 

And this is where Musk’s everything-app vision becomes particularly interesting. The convenience factor is incredibly appealing, but so is incentive to compromise it. And that’s the paradox we’re creating.

The more useful a single account becomes, the more important it becomes to protect, and the more damaging losing control of it could potentially be.

And the thing is, this paradox is relevant beyond this specific situation. We tend to treat convenience as an unquestionable good – after all, if an app can remove a step, combine two services or eliminate another password, that’s usually considered an improvement. It saves time and makes us more efficient, which is something we’ve positioned as the ultimate objective for so many years.

But perhaps there’s a point where convenience starts creating new risks. We don’t necessarily want five different apps just for the sake of having five different apps, but there may be value in keeping certain parts of our digital lives separate, particularly when financial information is involved.

 

The “Everything” App Experiment

 

It’s far too early to say that X Money has created a security disaster, becasue that’s simply true. We know that there’s currently no confirmed breach, and X says it’s investigating the password-reset activity. However, it may offer an early glimpse of one of the fundamental challenges of the everything-app model.

The more services a platform absorbs, the more attractive it becomes, and the more valuable the platform becomes, the more important its security becomes.

That’s not necessarily an argument against making technology more convenient, but it is an argument for recognising that convenience comes with trade-offs that absolutely need to be considered and mitigated.

Musk wants X to become somewhere people can do almost everything, but the question that we probably should be asking is whether one place for everything also means one place that attackers desperately want access to.