4 ms·
Unfortunately, good advice on this is going to be very hard to receive on hn/reddit etc. Discussions of how to do this properly require a lot of fine details. A
by peri 12y ago
Unfortunately, good advice on this is going to be very hard to receive on hn/reddit etc. Discussions of how to do this properly require a lot of fine details. A good introduction to this would be via the link posted by mooreds:
http://craphound.com/msftdrm.txt http://craphound.com/msftdrm.txt
Moxie Marlinspike's older post on the cryptographic doom principle, at http://www.thoughtcrime.org/blog/the-cryptographic-doom-principle/ http://www.thoughtcrime.org/blog/the-cryptographic-doom-prin... also covers some of the basics.
You're much, much better off getting expert advice on this from folks familiar with your SPA/JS Framework.
- junto 12y agoI've been trying to get my head around OAuth2 to see if anything in that is actually useful for this purposes. As far as I can see, 2-legged OAuth2 I.e. "Resource Owner Password Credentials Grant flow" is the type of flow I need, but it doesn't solve the malicious application problem.
- peri 12y agoYou need to talk to someone who will consult with you professionally to get good answers to this question, sorry.