Hacker News new | ask | show | jobs
by gravypod 2507 days ago
Signed and public-key-encrypred tokens
1 comments

Plus, use Windows' Protected Storage Subsystem (which has been around forever) to at least lock the tokens to a specific Windows account/user. No need for a machine-wide readable file even if the tokens were signed and encrypted.