Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Please just ask for that token and email over SSL. It's that simple. No need to risk people to lower user acquisition ramp.


You could, or you could just add a few round trips in the email thread and perform a handshake with the token HMAC encoded.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: