Hacker News new | ask | show | jobs
by pabs3 1214 days ago
The best practice is to leave the secrets on the customers systems and use asymmetric encryption (using FIDO2 or mTLS) to authenticate customers.