Like Google, I have been critical of OAuth 2 for some time, but now I have a compelling argument.
«Millions of Accounts Vulnerable due to Google’s OAuth Flaw:
Millions of Americans can have their data stolen right now because of a deficiency in Google’s “Sign in with Google” authentication flow. If you’ve worked for a startup in the past - especially one that has since shut down - you might be vulnerable.»
😬 trufflesecurity.com/blog/milli…
#google #oauth #login #websec #weblog #login #weblogin #itsec
=> kubikpixel | https://chaos.social/@kubikpixel/113833203275258489 | https://trufflesecurity.com/blog/millions-at-risk-due-to-google-s-oauth-flaw | Posts tagged #google | Posts tagged #login | Posts tagged #websec | Posts tagged #itsec
No replies.
────
=> 📡 Local feed | 🏕️ Communities | 🔥 Hashtags | 🔎 Search posts | 🔑 Sign in | 📊 Status | 🛟 Help This content has been proxied by September (ba2dc).Proxy Information
text/gemini