Hacker News new | ask | show | jobs
by logicuce 3076 days ago
It is not a bug with Google but instead a problem with "B" as they choose to ignore the "aud" part of the token.

You can't say password based authentication is bad because some developers choose to store password in plain text. The blame squarely lies with the developer.

People implementing auth without willing to go a little deeper may hurt themselves.