3 ms·
>> APIs do not need to sign every response, they just need to properly use HTTPS. > That doesn't make sense. The problem described in the article was that the
by speedplane 7y ago
>> APIs do not need to sign every response, they just need to properly use HTTPS.
> That doesn't make sense. The problem described in the article was that the request documents aren't signed, thus there is no way to verify if a response document was actually outputted by a web service.
Suppose that you ("System 1") is getting data from an intermediary ("System 2") which in turn is getting data from Twitter itself ("System 3").
Even if the intermediary System 2 signs the data, all that proves is that you got it from System 2. It does not prove that it was not tampered with when System 2 got that data from twitter directly, System 3. It would be easy for System 2 to tamper with the data, and come up with it's own signature.
If you, as System 1, want to confirm that the message you got from the intermediary (System 2) is authentically from twitter itself (System 3), you would need to get the signature from twitter directly. You would need to ask for twitter's signature (System 3's signature), not the intermediary's.
So system 1 will need to contact System 3 in order to validate the information it got from System 2. There's no way around this.