Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

How about short-lived access tokens and refresh tokens?


Depends on your usecase. On a device it's harder to steal a token, especially on iOS when you put all that stuff in the secured enclave.

Fortify that with certificate pinning on your application and it suddenly becomes REALLY hard to intercept traffic.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: