Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
lvh
on July 24, 2019
|
parent
|
context
|
favorite
| on:
How not to sign a JSON object
The nice thing about HMAC is that it's so bulletproof and easy to use. There are no footguns you introduce by using HMAC directly instead of using HS256, and there are plenty you introduce by using HS256 instead of plain HMAC.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: