Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Protecting Your Company From Phishing Attacks (meldium.com)
6 points by bradleybuda on May 8, 2013 | hide | past | favorite | 1 comment


The analysis is fair, but the conclusion is wrong. Nothing stops a phishing site from just luring you into granting it a lot of rights via OAuth. And if your OAuth server doesn't let your users use X or Y service, they will just sign up for it with a password anyway.

The solution is user education, not federated authentication (whether with two-factor authentication enabled or not.)




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: