4 ms·
OAuth is, like much of authentication and authorization that has been well marketed, very technically flawed. It makes a big show of not trusting the recipient
by _lex 10y ago
OAuth is, like much of authentication and authorization that has been well marketed, very technically flawed. It makes a big show of not trusting the recipient application with credentials, but anyone who's actually interested in stealing creds still can.
Plus it's way more complicated and has way more failure scenarios than simple password auth.
The only saving grace that I saw was that a service no longer has to store users' passwords to other systems, for persistent interaction with their data. I think this is really why people bother using it.
- supergeek133 10y agoUsername/Password is still the biggest security hole. With or without OAuth. One way to circumvent that would be to enforce password change after any oauth authorization, but that's not very user friendly.
- icebraining 10y agoIt makes a big show of not trusting the recipient application with credentials, but anyone who's actually interested in stealing creds still can. How so, if you're in a browser and you check the URL? It's only flawed here because the app controls the browser itself, but that wasn't the original use case of OAuth.