Hacker News new | ask | show | jobs
by martinko 1425 days ago
> I feel like a hash of the contents + some secret bytes could be a convincing signature that only the owners of the secret bytes could author.

How would you validate the signature?

1 comments

Parent is describing a keyed HMAC scheme. JWTs sometimes use them, but key management is a massive PITA.