HACKER Q&A
📣 MorL

Why is OAuth still hard in 2023?


Why do you think OAuth remains challenging even in the current technological landscape? Just yesterday, I came across a post discussing CVE-2023-28131, a vulnerability that has impacted hundreds of websites.

How can we address the recurring vulnerabilities and make OAuth more user-friendly and secure?


  👤 greenviad Accepted Answer ✓
CVE-2023-28131 was published in April.

But yes, great question

I think OpenId solves some of the issues, at least for authentication, not authorization.