Hacker News new | ask | show | jobs
by joelgascoigne 4619 days ago
The best thing we've learned here is to enable a setting Facebook has called "Require AppSecret Proof for Server API calls". They actually have a lot of great security features which we've not been making use of.