logoalt Hacker News

Retr0idtoday at 11:49 AM0 repliesview on HN

> A leaked token enables connections, but not impersonations. The token is addressed to one specific endpoint's public key

So now the problem is moved to "how do you decide who to issue tokens to?", which every project must solve individually. It might sound like I'm being dismissive here but I think that's exactly the right approach.