Handful of OAuth bugs combine for GitHub session theft
Almost two years after pointing out a public key vulnerability to GitHub, security researcher Egor Homakov has focused his attention on the service's OAuth implementation.
via Latest Topic for ZDNet in Security http://zd.net/1geR4Pd
via Latest Topic for ZDNet in Security http://zd.net/1geR4Pd