4 ms·
to me it speaks more about poor security auditing. Treating the User ID as a public key instead of a private one to me signals lax security policy.
by chrisrogers 12y ago
to me it speaks more about poor security auditing. Treating the User ID as a public key instead of a private one to me signals lax security policy.
- smt88 12y agoClient-side code (even native apps) must be considered public. That means your API is also publicly discoverable. A user ID is fine to use as a public key, but it must be paired with something private. Generally some sort of unique, crypographically-secure auth token is fine when combined with forced HTTPS connections.