Skip to content

Comment on When REST isn't Good Enoughparent

Comments

I can understand that a payment gateway takes security more serious, as it can directly affect their business if clients handle SSL wrongly.

Maybe a kind of chaos-monkey for API connections could help? Every now and then the API returns a wrong SSL certificate. If the client ignores this, they could notify the customer, or directly block further access until the problem is solved? :)

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.