Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I assume a combination of public/private keypairs and timestamping.

If you trust the client to say "yes, validate via the keygen.sh API", then without loss of generality you can probably trust it to validate using a public key and a timestamp.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: