Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

client credentials threat is OAuth1 too.


Right, but other oauth2 providers than facebook aren't vulnerable to the redirect_uri hack you are describing, are they?


not sure, i didn't check all of them

also facebook is 90% of oauth




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: