The verify response has a signature field. Is checking it actually necessary if I'm already on HTTPS?
DH
Derek H
Question Aug 31, 2026
The verify response has a signature field. Is checking it actually necessary if I'm already on HTTPS?
HTTPS proves you talked to us. The signature proves the answer you're holding is the one we gave, and the nonce proves it isn't one we gave an hour ago being replayed at you.
If the answer never leaves the request that fetched it, HTTPS alone is close enough. The moment you cache it — and you should — check the signature, because a cached answer is exactly what's worth tampering with.
Sign in to reply. Posting needs an account so threads can be moderated and so answers have a name on them.
Sign in Create an account