Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> 4. If, like last.fm, you were also allowing third-parties to authorize users...

... then you should stop doing that and you should start using OAuth, so the client application never sees your user's password.



Theoretically, sure. But I can't think of a nice way to authorise users on something like [1]. They'd then need a computer with the radio to provide some kind of access code, I guess?

[1] http://www.robertsradio.co.uk/Products/Internet_radios/STREA...


One time passwords (feed the radio your generated password & let it use that to negotiate authorisation/api keys).


Why do you write/footnote like that? Is there a geographical disparity in how to footnote?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: