3 ms·
My submission was unnecessarily terse. Thank you for expanding upon it. I agree with all your points about OAuth2 clients. But I would also add: All clients (
by DanielDent 9y ago
My submission was unnecessarily terse. Thank you for expanding upon it.
I agree with all your points about OAuth2 clients. But I would also add:
All clients (Amazon official or not) will ultimately need to have API keys compiled into them, and/or use a (less secure for the user) remote service to do the OAuth flow.
And for all of these clients, it will be possible for users to obtain the keys with some very simple reverse engineering and/or protocol analysis.
Which makes this entire thing seem like a real waste of everyone's time. Provide an API/service available on the internet, or don't.
Trying to tell people exactly which configuration of which software they should use to access your service is both disrespectful of your user's freedom as well as a fool's errand.