Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Quote from the original documentation: "The recommended strategy is to share the keys automatically only to verified devices of the same user. Requests coming from unverified devices should prompt a dialog, allowing the user to verify the device, share the keys without verifying, or not to share them (and ignore future requests). A client should also check whether requests coming from devices of other users are legitimate." - It made me smile, because should and recommended doesn't generally mean anything to developers. Only mandatory, must and must not, sections might get some attention.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: