Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
What people don't understand about OAuth (scripting.com)
3 points by davewiner on Sept 11, 2010 | hide | past | favorite | 1 comment



It's Twitter's decision that each 3rd-party gets full "be you" permissions; they could choose otherwise and still use OAuth.

And the fact that everything done by a bad actor can be attributed to them -- for reversal or blanket punishment -- does add a lot of security, in addition to the party-at-a-time revocability.




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: