Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

FTA:

> While Google implemented multiple mechanisms, like two-factor-authentication, to prevent hackers from compromising Google accounts, a stolen authorization token bypasses this mechanism and allows hackers the desired access as the user is perceived as already logged in.

The trouble is that auth tokens are generally not tied to a specific device or IP. There aren't really any mechanisms for this in standard OAuth 2.0 flows (if indeed this is what they're using).



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: