Hacker News new | ask | show | jobs
by JoshuaRogers 1240 days ago
Mainly because of "Login with Twitter". There isn't a proper way to tell downstream systems who have authenticated against Twitter that "The account JohnDoe is now a different user than they were."

Basically the same principle used to hijack accounts by buying an expired domain that had email addresses associated with it.