3 ms·
Reading from other comments I think it goes as follows: This is related to SSO (single sign on) where imgur didn't check the source of the token. So, if you b
by TrianguloY 3y ago
Reading from other comments I think it goes as follows:
This is related to SSO (single sign on) where imgur didn't check the source of the token.
So, if you built an app that used SSO with Facebook (so that any user can log into your app with their Facebook credentials, but without you knowing them) you could use that SSO information for your app to log into imgur as that user.
Because imgur wasn't checking that the token was from their own app. The token is just a Facebook response that says something like "this is user X and they wants to log into app Y, signed by Facebook". If you don't check Y...