
Search Engine Vulnerabilities, Ghost Tokens, Anna Kournikova
Hacker And The Fed
00:00
The Ghost Token: A Backdoor to Your Account
OAuth is an authorization protocol. When you see stuff like logging with Facebook and you log into another application and it uses your Facebook credentials to get to you, that's OAuth. But now there's the single sign on. Single sign on is not a protocol. It's another concept for using multiple service providers with one login. We can log into multiple services using the same credentials.
Transcript
Play full episode