4 ms·
The website does get your credentials. To be fair, this is how password login with any of the web clients works as well. Which makes it hazardous to use clients
by heftig 5y ago
The website does get your credentials. To be fair, this is how password login with any of the web clients works as well. Which makes it hazardous to use clients not hosted by the homeserver or a trusted third party.
However, if the homeserver is using OIDC, the user credentials are handled entirely by the external OIDC provider and the client doesn't get them. But then you should be using OIDC directly and not "Sign in with Matrix."
- driminicus 5y agoWe are actually working on fixing the password sending issue, see for instance https://github.com/matrix-org/matrix-doc/pull/3262 https://github.com/matrix-org/matrix-doc/pull/3262 Of course, untrusted clients can do all kinds of evil things after having authenticated. (And also clients still need the plaintext password at least client-side no matter what we do)
- detaro 5y ago> (And also clients still need the plaintext password at least client-side no matter what we do) Are matrix devs seriously not aware of what OAuth is and does? That is ... concerning.
- driminicus 5y agoMatrix does actually support OAuth (in fact, the mozilla.org matrix server can only be logged in to through OAuth)