You can steal a JWT token the same way you can steal a session token.
38 karma · joined May 23, 2016
You can steal a JWT token the same way you can steal a session token.
For ephemeral messaging like a SnapChat type use case, you can EASILY provide p2p encrypted. For services like Telegram and FacebookMessenger, their feature list requires cross device syncing, historical archiving, and those features don't play well with rotating keys, perfect forward secrecy, and other e2e encrypted messaging techniques.
What channel would you use to share the keys on FB? The Facebook API simply will not let you do that anymore. Direct messages have a character limit and you can't just post to someone's wall anymore.
I tried working on something like this for seecret.io but was confounded by the Facebook API's limitations.
Twitter is much better for that. Probably other network too.
Distributed open-source clients that use end-2-end encryption over third party messaging channels is the future of secure messaging.
The future of trusted secure messaging will be open source, auditable, independent non-native clients that connect and send over third party message channels independently.
This may be pretty obvious but it's not quite the terrible analysis of relying on just #4.
1. Get and manipulate dom elements. 2. Register simple event handlers 3. Ajax calls that are simple (frankly all other ajax-ish APIs I've ever seen pretty much copy the design and approach of the JQuery one).
Also a pretty big ecosystem of simple highly focused add-ons. You (still) can get a long way with just JQuery
Typically, the team manager will just have his team members all interview the candidate. They will have no prep, no guidance, nothing. Just "interview this person and tell me your decision".
No one asks the candidate any questions relevant to the actual work the candidate will be expected to do on the job. It's mostly sorting algorithms and trick questions about regex etc. All stuff they encountered in CS101 and in THEIR interview 2 months before....
For browser work, you can do almost everything you need with some jQuery, handlebars and moment if there are dates. A few other small libs here and there and you've got almost everything covered. Some edge cases may drive you to use some library that is heavily dependent on 32 different sub-libs but it's really not that often.
Server-side Node.js is the issue, not browser compatibility.
That's not necessarily true. End to end encryption doesn't need to be a compiled mobile app or send messages over a closed platform.
We built a decentralized, open source, freely distributable, browser-based Twitter client utilizing end-to-end encryption at www.seecret.io specifically to address that.
edit: but other non-profits will typically pay much lower.