Hacker News new | past | comments | ask | show | jobs | submit login

Incorrect. The consumer-secret and access-token-secret are not transmitted from client to the server during oauth. They are only used to sign requests.



Clarification: For v1. In v2 the secrets just go over SSL.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: