3 ms·
Ooh this is a favorite pet peeve of mine. HMAC is the better solution IMO but API Keys are so much easier for your customers to use: - API Keys are much, _much
by maxwellg 1y ago
Ooh this is a favorite pet peeve of mine. HMAC is the better solution IMO but API Keys are so much easier for your customers to use:
- API Keys are much, _much_ easier to use from the command line. CURL with HMAC is finicky at best and turns a one-liner into a big script
- Maintaining N client libraries for your REST API is hard and means you'll likely deprioritize non-mainstream languages. If a customer needs to write their own library to interact with your service, needing to incorporate their own HMAC adds even more friction.
- Tools have gotten much better in recent years- it is much easier to configure a logger to ignore sensitive fields now compared to ~10 years ago
- growse 1y agoAPI keys are just Basic Auth wearing a silly hat. There's so many better options than just dumping the secret on the wire.
- arccy 1y agoif you copy the aws signing, curl has --aws-sigv4
- lo0dot0 1y agoWhat's the advantage of HMAC over basic auth when TLS is used as a transport?
- kevincox 1y agoIn theory nothing. If you have complete confidentiality you only enough entropy to ensure that the attacker can not guess it. But in practice things get logged, people mess up their DNS and send the request to a different party (potentially after their CDN decrypts it) or some other blunder. With HMAC as long as the recipient is validating properly (which is a whole different can of worms) the worst the attacker can do is replay requests that they have observed.
- deleted 1y ago[deleted]