Right, but that doesn't compromise the security of the service necessarily.
Users can catch a malicious server injecting incorrect keys by looking at security notifications and comparing security codes. This is part of the Signal protocol.
This may be tedious but only needs to be done in the event of phone keys getting reset (a once in a year event?), as all companion device keys are automatically verified with signatures provided from an account owner's primary (phone) device
Would e2ee really be guaranteed if a user sets an 8 char password? Because if so an attacker with control of the server could brute forcedly decrypt the encryption key, and in turn all DB contents for a user, no?
Apologies if this is covered somewhere in the docs, but I couldn’t find it.
From what I can read on the twit and GitHub, the researcher hasn't proven this works at scale.
The point of recaptcha is blocking "captcha farms" or automated bots from abusively creating accounts, buying tickets, etc.
The author hasn't demonstrated that this attack is effective in those scenarios. The only thing he has shown is a very convoluted way for a human to solve a recaptcha (harder for 99.9% of humans than the standard recaptcha experience)
That would explain why Google didn't care about them publishing this.
I'd say the syntax is halfway in between Java and Scala. That makes it much more approachable for Java developers (you can learn the basics in an afternoon), but also less flexible than Scala sometimes.
This is a translation of an original talk in Spanish from the security congress RootedCon. If you understand Spanish, do watch the spanish version here: https://www.youtube.com/watch?v=6ZoDKsxPM08
TL;DW: He proves how with a jailbroken device you can extract feature points of fingerprints stored in the Secure Element, or override Touch ID sec. completely (as an example, he unlocks a device with his nose)
And just before anyone points it out, I know that Node JS, Backbone, Coffee Script and Angular have little to do with each another.
I did the comparison with them just to put in perspective what is the popularity and growth of Angular, in comparison to other Javascript related things you might know better.
> Discord is a close second. But the quality and polish of telegram blows me away to this day.
User experience is, well, subjective to the user. For tech savvy, primarily desktop users, Telegram and Discord can be great choices.
This is however probably not true for the majority of the population.