Skip to content

Comment on Getting started with designing a Secure REST (Web) API

Comments

Does anyone have any comments on protecting the private key / API in an unsecure client (such as Javascript, or a mobile app where the source code can be readily viewed)? He mentions it in this article, but no one seems to address it in the comments and the solution offered of "reset the private key" doesn't seem terribly secure.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.