Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Which is apparently exactly what Facebook does with this thing.


To be fair it looks like they aren't purely using SSO which is what provided the credential scrapping attack vector that was used by someone else.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: