#1 Why allow HTTP, rather than limiting to HTTPS ?
#2 And if they were to limit themselves to HTTPS, would they still create their proprietary HMAC, instead of OAuth or BasicAuth+SSL ?
Greg Brail
unread,
Oct 9, 2012, 11:11:34 AM10/9/12
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to api-...@googlegroups.com
I don't work there but:
#1 Why allow HTTP, rather than limiting to HTTPS ?
S3 (which was one of their very first APIs if not the first) lets you upload and download gigantic files and I presume that they figured the cost, quite a few years ago, of doing this with SSL would be prohibitive.
#2 And if they were to limit themselves to HTTPS, would they still create their proprietary HMAC, instead of OAuth or BasicAuth+SSL ?
Their longest-lived APIs like S3 were in production a few years before OAuth was invented.