Handful of OAuth bugs combine for GitHub session theft

Almost two years after pointing out a public key vulnerability to GitHub, security researcher Egor Homakov has focused his attention on the service's OAuth implementation.



via Latest Topic for ZDNet in Security http://zd.net/1geR4Pd