Hacker News new | ask | show | jobs
by dawkins 4480 days ago
I meant for a native app and you being the provider. If you don't trust the client app even oAuth won't help you preventing the client app to know the user password.
1 comments

It is true you have to trust that the native app is not tricking you into thinking that you're entering your password on Facebook.

But, at least if it's implemented correctly and not maliciously, the app doesn't ever see your password.