Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> and revoke API keys sent over the unencrypted connection.

Excuse me, short question:

If I am not offering a non-TLS endpoint in the first place, and the client, for some reason, decides to take something that is literally called "SECRET", and decides to shout it across the open internet unencrypted...

...how is that my problem again?

Why should my setup be more complex than it needs to be, to make up for an obvious mistake made by the client?



Consider applying for YC's Winter 2026 batch! Applications are open till Nov 10

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: