logoalt Hacker News

gonzalohm • today at 12:16 AM • 2 replies • view on HN

I don't have the code at hand, but I think it's better to just have a nginx server that only serves content if the browser has a specific certificate installed. That way you generate a key pair, share the public key with anyone that you want to share the content with and that's it.

Downside is that some browsers don't handle the certificates properly (especially on phones)


Replies

jagged-chisel • today at 1:42 AM

An HTPS server always hands out its public key. Do you mean client secrets or something?

➕ show 1 reply