#Oops. "Login with Google" can be abused if you buy a domain name that formerly had accounts, e.g. from a failed startup.
"At the time of writing, there is no fix."
https://trufflesecurity.com/blog/millions-at-risk-due-to-google-s-oauth-flaw
#Oops. "Login with Google" can be abused if you buy a domain name that formerly had accounts, e.g. from a failed startup.
"At the time of writing, there is no fix."
https://trufflesecurity.com/blog/millions-at-risk-due-to-google-s-oauth-flaw
@jwildeboer same for buying old domains where the email has been used too register an account without SSO, and can still be used to reset the password, what’s new?
aside of the fact that lots of services do not allow your sso provider to be changed
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.