3 ms·
(I'm the author of the article) HTTPS is definitely recommended. I would however recommend against using a hash of a pass phrase since it would have the same ef
by thecodemonkey 13y ago
(I'm the author of the article)
HTTPS is definitely recommended. I would however recommend against using a hash of a pass phrase since it would have the same effect as an API key (you would still be able to replay it), and we all know that hashes without salts never go well :)
- abrichr 13y agoI figured the salt went without saying ;)
- sjtgraham 13y agoNot if you use HMAC
- feralmoan 13y agoJWT is an interesting standard (http://tools.ietf.org/html/draft-ietf-oauth-json-web-token-19 http://tools.ietf.org/html/draft-ietf-oauth-json-web-token-1...) dealing with sessionless temporal auth tokens that offers some flexibility between http basic (native) or signed tokens using the same credentials. If you're not using TLS you're kind of screwed anyway, whatever the auth scheme!