Now your talking about hackers instead of spammers. It is hard to
sniff a HTTP session, you have to penetrate your victim's network
enough to be able to do so.
You're assuming that the application is only ever used in a trusted
environment, which is unlikely to be the case. If an attacker can
download a copy of the application, there is no way to prevent them
from reusing credentials which are embedded in it.
_______________________________________________
Cocoa-dev mailing list (email@hidden)
Please do not post admin requests or moderator comments to the list.
Contact the moderators at cocoa-dev-admins(at)lists.apple.com