3 ms·
Strongly recommend reading this, as well as looking up Homakov's exploits. My opinion is that OAuth 2.0 is a very bad spec because in practice people do not imp
by peter_l_downs 3y ago
Strongly recommend reading this, as well as looking up Homakov's exploits. My opinion is that OAuth 2.0 is a very bad spec because in practice people do not implement it correctly. As to why? Maybe it's that the spec is split across multiple RFCs, and defines many insecure behaviors as compliant, and authorization is just hard.
When Facebook, Twitter, Github, etc. all got burned at various points in time with their OAuth implementations, you have to start looking for the common denominator.
- lylejantzi3rd 3y ago> My opinion is that OAuth 2.0 is a very bad spec because in practice people do not implement it correctly. Can we just stop using oauth entirely, then? There's got to be something better.
- paulddraper 3y agoOauth 2.1 > Keep in mind that when OAuth 2.0 was published in 2012, the iPhone 5 was brand new, the latest browser from Microsoft was Internet Explorer 9, single-page apps were called “AJAX apps”, and CORS was not yet an established W3C standard.