Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This serial number protocol seems deeply insecure.

The server should be sending a ticket, an encryption of the serial number, to the client, and expecting that back. It should be salted by the client id.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: