Security flaw in OAuth and OpenID
-
http://www.cnet.com/news/serious-security-flaw-in-oauth-and-openid-discovered/#ftag=CAD590a51e
Seems like a biggie, especially since they are saying they won't/can't fix it.
-
Wow! That's crazy.
-
everything i read so far is saying that people have tried alerting google and facebook but they aren't responding. Why don't people respond to glaring security holes?
-
It just seems hopeless sometimes.
-
I've always shied away from the option to "Login with your [Facebook/Twitter/Linkedin/etc] Account", mainly because of privacy concerns, but also because I've heard of design flaws with the OAUTH and OpenID systems (mainly from listening to Steve Gibson's podcast)