4 ms·
Oauth tokens, consumer keys, nonces, and timestamps are not something you don't already have access to as a user. The token is your authentication proof / API a
by metoosorta 14y ago
Oauth tokens, consumer keys, nonces, and timestamps are not something you don't already have access to as a user. The token is your authentication proof / API access key, the consumer key is a bit misleadingly named but just identifies the 3rd party, it is public knowledge. The nonce and timestamps are artifacts of authentication and less sensitive than the token.
The real meat is the 3rd party's consumer secret (the secret key that goes with their consumer key.) If you're finding those then someone needs to make a South Park ski instructor meme.
- maqr 14y agoThis should be the top comment. This blog post just shows URLs, which are the result of being signed with the 'consumer secret'. You can see the same thing with wireshark, charles, or any other sniffer or debugging proxy. The more important thing is the consumer secret itself, which is discussed here: http://stackoverflow.com/questions/4419915/how-to-keep-the-oauth-consumer-secret-safe-and-how-to-react-when-its-compromis http://stackoverflow.com/questions/4419915/how-to-keep-the-o...
- rmccue 14y agoYou shouldn't be able to see it with Wireshark, given that it's HTTPS, but you should be able to MITM it (assuming you can make yourself a CA, that's trivial).
- tommoor 14y agoagreed, this post doesn't show any information you don't have permission to know being the authorised user of the application...