In this case the only way to do HN Login is for 3rd-party to manually handle the login credential and do a POST to https://news.ycombinator.com/login to obtain an omnipotent token that expires in 18 years.
Doesn't this post a sercuirty risk? Shouldn't third-party service providers inform users about this? Or is it a common practice to not mention things like this to the end users? (All the HN apps I have come across with amazing ratings have 0 mention about this risk on their app page and inside the app.)
Or is there another way to do HN Login that is safe and I'm simply not aware of?