Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

He suggests KISS: you can probably get away with plain old server-side auth, and if you really need client-side tokens, use something simple that just encrypts and signs them: https://news.ycombinator.com/item?id=13612941#13615634


> Something simple that just encrypts and signs them

Like JWT?

I feel like that argument goes around in circles.



> I feel like that argument goes around in circles.

I feel that the problem is that some users are talking about stuff they know nothing about, but still feel compelled to be very vocal and opinionated.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: