Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Didn't any qualified security researchers do a security assessment of OAuth when it was in development? This spec was finalized in 2007 which means we've had at least two years to find this obvious problem.

We've known from the start that OAuth and OpenID are vulnerable to various social engineering attacks, and I guess the communities using each have accepted that as the lesser of two evils. But, you know, somebody has to check that the protocol actually works at least a little.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: