you are viewing a single comment's thread
view the rest of the comments
[–] 2 points 16 hours ago (1 child)

I think the real way to do this would be to set the secret to a specific, external api token. Any sort of password or internal mechanism is going to be leaked.

Although, you could still pull the ol "pretend you received an a-ok response from the API..."

  • source
  • parent
  • hideshow 1 child comment
  • [–] 1 point 16 hours ago

    Well, in general, AI techniques can be used to further lock down scenarios that are tricky to detect in traditional cases, but the traditional access controls are more reliable at preventing access when applied, so absolutely both techniques is the practical answer.

  • source
  • parent