Hacker News new | ask | show | jobs
by rpearl 4105 days ago
We're getting pretty far off-topic here, but please note that "a sha256 hash of the parameters and a serverside secret" is insufficient for authentication: http://en.wikipedia.org/wiki/Hash-based_message_authenticati...