Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

it is relevant — for Stolen Credentials threat.

if you have creds you can obtain access token for ANY redirect_uri, even for leaking. if it would be static it would not be possible to leak it at all



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: