Why do web APIs tend to use pre-shared keys for client auth instead of pubkeys? | Hacker News Reader