3 ms·
i don't see any reason to 'sign' a request over HTTPS if you're going to implement authentication. hmac / signing makes sense if you can't afford the overhead
by jgavris 15y ago
i don't see any reason to 'sign' a request over HTTPS if you're going to implement authentication.
hmac / signing makes sense if you can't afford the overhead of SSL, and don't mind exposing the request to a man in the middle / eavesdropper.