Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

oauth would have request replay prevention or there could be some other ways of stopping the count fraud, but app_secret is probably always available in some kind of readable form. This is just an aspect of mobile security we have to live with. Facebook 3 party sign-on helps a little here because one could check requests server-side against valid temporary FB keys. But Fukime cow counter could easily do without those :)


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: