Researchers took over Booking.com accounts using a legitimate Facebook link

https://news.ycombinator.com/item?id=35003045
by aviCC • 3 years ago
4 1 3 years ago

The vulnerability exists in OAuth (social sign-in), used by almost every website today. If you are unfamiliar with OAuth, the post (in the first comment) explains it step-by-step with detailed diagrams.

Related Stories

Loading related stories...

Source preview

news.ycombinator.com