Skip to content

Comment on The Problem With Client-Side Analytics

Comments

First, that's not a "digital signature", it's a MAC. It's the secret-suffix SHA1 MAC, to be precise.

Second, the secret-suffix SHA1 MAC isn't secure. Its insecurity is the reason we have HMAC.

This seems to me to be the kind of thing you'd want to get right if the whole value proposition of your solution was "verifying URLs with cryptography".

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.