Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
nurple
on Oct 22, 2023
|
parent
|
context
|
favorite
| on:
Stealing OAuth tokens of Microsoft accounts via op...
All they had to do was add and validate a nonce value in the state, or at the very least, to triage, sanitize the subdomain value. The latter would literally be a 10 minute fix.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: