Wow! I'm surprised the attacker(s) burned the clever oauth phishing trick without much targeted purpose.
-
-
Replying to @kevinmitnick @hacks4pancakes
I'm skeptical that it's "burned". The OAuth protocol fundamentally facilitates things like this. We'll likely see waves of new variants.
2 replies 0 retweets 4 likes
Only way to fix is to get rid of the ability to grant permissions by click-thru, reduce OAuth functionality to be OpenID-equivalent.
8:44 PM - 3 May 2017
0 replies
0 retweets
1 like
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.