Hacker News new | ask | show | jobs
by andybak 2101 days ago
Yes. A thousand times yes.

oAuth outside a browser is just training people to be phished.

1 comments

It's not just limited to webview's and tech companies.

When my bank calls me up about an issue with my account, they won't talk to me unless I give them my date of birth and email address for 'data protection' purposes.

They're always really confused when I say I will have to call them back.