Hacker News new | ask | show | jobs
by talklittle 4425 days ago
Not sure if this is news. The lead author of OAuth 2 resigned from the OAuth working group 2 years ago, citing all the security flaws inherent in the OAuth 2 spec.

http://www.cnet.com/news/oauth-2-0-leader-resigns-says-stand...

OP just spells out one way to take advantage of OAuth 2, and tacks on a sensational title.

1 comments

Agreed; I thought that the general consensus was that OAuth2 was severely flawed (and why many sites stuck with OAuth1). Been a few years since I worked with OAuth though, so I could be wrong.
OpenID-Connect is the most current spec in that world.