Hacker News new | ask | show | jobs
by unilynx 3216 days ago
It's not just madness, TLS is a MUST in several places in the oauth2 spec.

In fact, they managed to remove a lot of oauth1 madness (all the complex signing stuff) by simply requiring TLS and let that layer deal with it.