作为restful web api 服务器,我们为我们的客户端提供一个clientid 和密码。我认为客户端使用 clientid + hMAC(clientid hashed by password) 进行身份验证就足够了。
我查看了一些建议使用时间戳或更多信息的文档作为基本字符串。我只是无法理解那是什么意思。
任何大师都可以帮助解释确切的时间戳有助于防止攻击或其他任何事情吗?
authentication timestamp hmac
authentication ×1
hmac ×1
timestamp ×1