3 ms·
I am not sure if you know this but when a "website" asks you for your api key (youtube api key in this case), they encrypt and store it somewhere else like a va
by itsDhruvv 3y ago
I am not sure if you know this but when a "website" asks you for your api key (youtube api key in this case), they encrypt and store it somewhere else like a vault storage by 3rd party regulated storage services (Like one which Amazon provides), so I don't see how a "website" can misuse the access via keys :)
Thanks for sharing your thoughts though
- KomoD 3y agoWhy are you putting website in quotes? And no, not everyone stores it securely. And yes, they totally can misuse the access
- starkrights 3y agoThe problem is that anyone can make a website that asks you for your API key and promptly does none of this- you recognize this, right? You can say that “trustable” websites don’t do that, but that’s the point- why would anyone trust your random website when you could either be A) malicious, and purposefully steal their stuff (unlikely) or B) stupid, and fuck up their crypto and/or any of the other million moving parts in webdev security that people fuck up and end up leaking any arbitrary amount of data (extremely, comically likely) Now you could’ve just worded your response badly or we could’ve misinterpreted your words severely, but it sounds like you’re claiming that people just get it right every time someone makes a website. Even if we didn’t think A was likely, that line of thought doesn’t instill confidence that B is unlikely. Also you absolutely would NOT ask a user for their API key. The fact that you don’t immediately think you’d be using an OAuth authentication flow and getting a bearer token on behalf of the user is terrifying. The API token is for YOUR application. —— Abject negativity over- your concept isn’t bad, and I kinda like it. You should pursue it, especially under the advice about what your outreach/advertising game is going to look like, given elsewhere in this thread. Please dear god though, talk to or hire someone who knows what they’re doing with webdev security if you’re going to deal with actual user bearer tokens- it doesn’t sound like you’ve ever built an application like this before, and you can make a million fatal missteps along the way.