3 ms·
Yes. That's true - if your source code is exposed to a client. Going back to my example of Twilio apps, usually the code that interacts with Twilio is on the se
by RossPenman 13y ago
Yes. That's true - if your source code is exposed to a client.
Going back to my example of Twilio apps, usually the code that interacts with Twilio is on the server side, so you couldn't find the API keys by viewing source.
- kelnos 13y agoAnother thing we (Twilio employee here) do, for our Client product, which runs on iOS and Android, we use a different form of authentication: we require a server-side component to generate a "capability token" which is signed by your main auth token. The capability token is limited in what it can do, and expires after a configurable amount of time, so if an attacker gets hold of one, the damage they can do is limited. Of course, people can "cheat" and put their auth token and a capability token generator in their mobile app, but we try to discourage that use.
- tlarkworthy 13y agoI am loving Firebase's serverless model of application development, so that server solution is not ideal. But I don't think its possible to solve a different way. That said, there are smart people who have thought of ways of reducing server burden in ways I never thought possible (like encrypted sessions), so it might be possible ??? How does google analytics stop rogue clients registering hits on the wrong domain? It checks the domain the incoming data is on, right? (cookies?)