Skip to content
This repository has been archived by the owner on May 6, 2020. It is now read-only.

MITM attack or inconsistent font between Riot Desktop and Riot Android? #286

Open
Mikaela opened this issue Apr 12, 2019 · 1 comment
Open

Comments

@Mikaela
Copy link

Mikaela commented Apr 12, 2019

I changed my password and added two devices, Riot desktop from Flatpak and Riot Android. Then I proceeded to verify the devices and I see these:

photo_2019-04-12_16-48-00
photo_2019-04-12_16-47-52

Note particularly the three last characters. Are they 1WM or IWM (or even lWM)? I cannot say, so was my new password leaked immediately, is Matrix.org homeserver attacking me or is there just a bad inconsistent font between the two clients?

  • riot-web version: 1.0.7 via Flathub on Debian Testing
  • Riot Android 0.8.29 via Play Store
@jryans
Copy link

jryans commented Apr 12, 2019

It looks like a font / display issue to me. Riot Android should probably use a monospaced font (like Riot Web) so it's easier to compare characters in the device key.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants