Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Good question. I dug up the e-mail from 2012 and here's what the Google Security Team told me:

> We're deploying some abuse detection and reactive measures to deal with impostors that might try to abuse this sort of attack.

Surely any OAuth2 service provider will disable clients that are caught misbehaving.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: