5 ms·
What would you use an HMAC generated in JavaScript for? I'm trying to think of uses that wouldn't be completely insecure, but I'm coming up empty. You need to h
by robbles 14y ago
What would you use an HMAC generated in JavaScript for? I'm trying to think of uses that wouldn't be completely insecure, but I'm coming up empty. You need to have the key client-side, so what's the point?
- hexasquid 14y agoI imagine this is not sent to the client, and is used for serverside JavaScript applications.
- pjscott 14y agoIn server-side JavaScript, you'd typically have easy access to non-JS crypto libraries. In node, you have the crypto package, which is a thin wrapper around OpenSSL. In Rhino, you can use Java libraries like Bouncy Castle. And so on.
- ushi 14y agoWhat about a browser extension, where you enter some api key, before you can use it.
- angryasian 14y agothe only situation I could possibly think of is that the key is a user input and the digest is only sent to the server. Then the server could verify knowing that customers key.