3 ms·
Isn't the fact that they are using a simple HMAC-SHA256 hash also a root of the problem? If instead of using the POST data only to create the hash they added a
by rnaud 13y ago
Isn't the fact that they are using a simple HMAC-SHA256 hash also a root of the problem?
If instead of using the POST data only to create the hash they added another information, like a the hour of the day. Wouldn't it be way harder for a hacker to actually understand what went into signing the request?
- meritt 13y agoNot really. He decompiled the code so it's pretty simple to figure out regardless.