DEV Community

Discussion on: How to minimize security concerns in your applications

Collapse
 
exadra37 profile image
Paulo Renato

Sessions can be reused by an attacker, but definitely it makes up for one more security layer to be bypassed, and I always recommend to use it when possible.

Other techniques exist to make them more difficult to abuse, but an API key on their own, can only be considered secure for authentication purposes when the communication is between 2 servers, and they are stored in both servers in a secure way.