Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I don't know about that — it helps to have more than superficial knowledge of the topic at hand so that you can adequately assess rants such as this one.

Personally, while I feel that Igor Homakov has done good work, this article is the product of frustration and is a disservice to its audience. Most if not all of his criticisms of OAuth 2 come down to implementation problems, and a more positive contribution would be an implementers' guide or a threat model document. For example, https://tools.ietf.org/html/rfc6819 and http://leastprivilege.com/2013/03/15/common-oauth2-vulnerabi....



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: