Hacker News new | ask | show | jobs
by r3bl 3819 days ago
> This is perhaps a general question about 3rd-party auth, but how am I supposed to trust an app like this when I click "log in with google/github/etc"? I'm simply shown a new pane within the same application that could easily be a phishing attack. There's no way to verify who the hell I'm sending my user/pass to.

I see this happening over and over again on my phone. Especially with Facebook logins.