Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My understanding from my research into OAUTH2 is that most of the vulnerabilities in it are only issues in a naive implementation. They can be made secure, but it's not easy and you have to know to do it in the first place.

Doesn't OpenID Connect address those issues? I know that's what Google is using now.



Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: