Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Why do web APIs tend to use pre-shared keys for client auth instead of pubkeys? (crypto.stackexchange.com)
2 points by zhxshen on Sept 13, 2022 | hide | past | favorite | 1 comment


Why don't APIs support IP address authentication?

For APIs focused on server based apps, this should work as well as anything else.

It's not possible to duplicate an IP --- the communication gets broken. If the server gets compromised --- well, any pre-shared keys are likewise compromised so the result is the same.

There are a few services that support this but not very many.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: