4 ms·
You missed the obvious: using OAuth2 without TLS =) And paranoid part of my brain suggests that using OAuth1.0a is still preferred even if over TLS
by indeyets 12y ago
You missed the obvious: using OAuth2 without TLS =)
And paranoid part of my brain suggests that using OAuth1.0a is still preferred even if over TLS
- homakov 12y agoThis is another kind of threat but yes, MITM is game over for oauth2