Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Often, Y has access to X either way, because Y is where the password reset email goes.


A password reset doesn't go unnoticed. A fake OAuth login very much can. I would be very surprised if no OAuth provider ever did that.


That's a good point.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: