4 ms·
OAuth has been called flawed by security experts because it's filled with trap holes for developers to fall into[1] and former developers who left the project[2
by qompiler 14y ago
OAuth has been called flawed by security experts because it's filled with trap holes for developers to fall into[1] and former developers who left the project[2].
1. http://homakov.blogspot.jp/2013/03/oauth1-oauth2-oauth.html http://homakov.blogspot.jp/2013/03/oauth1-oauth2-oauth.html
2. http://en.wikipedia.org/wiki/OAuth#Controversy http://en.wikipedia.org/wiki/OAuth#Controversy
- eli 14y agoSure, but that's beside the point. OAuth does not attempt to deal with this problem. If you have the secret consumer token, then you are that consumer in the eyes of OAuth.