logoalt Hacker News

jen20today at 4:06 AM1 replyview on HN

It was simple(ish) 20 years ago, to be fair.


Replies

thaynetoday at 4:26 AM

Simpler than it is now, but the authentication system was never simple. You can't just put a bearer token in the authorization header, you have to follow a complicated algorithm to sign the request. That made some sense 20 years ago when s3 didn't use tls to protect against a mitm that changed the changed the request. It is less valuable now when you use tls.

show 2 replies