Skip to content
Better HN
Top
Best
Ask
Show
New
Jobs
Search
⌘K
0 points
4death4
2y ago
0 comments
Save
Share
Even if the copy the header, they can only perform a replay attack, which is an improvement over leaking an API key. Also, you could include a timestamp in the signature to limit the amount of time it could be replayed.
0 comments
1 comments · 1 top-level
top
newest
oldest
dcow
2y ago
Sign a nonce.
j
/
k
navigate · click thread line to collapse