Hacker News new | ask | show | jobs
by ushakov 1683 days ago
one big reason there are things like “Sign in with x” is so that the application can do things on user’s behalf
2 comments

Yes, with controlled permissions the user can clearly decide about. Nothing gives you full access over an account.
This is like disabling MFA and giving you my google username and password. Actually it's worse than that because Google would probably ask me for an email verification code. Try adding this to a phishing/social engineering framework, they will be impressed.