TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Hackers use OAuth, fake Google apps to phish users

7 点作者 willow9886大约 8 年前

2 条评论

chatmasta大约 8 年前
Relatedly, be very careful which apps with &quot;native browsers&quot; you enter 3rd party credentials into. For example if you install an app and it opens a WebView with the google login screen, the app can read and write any arbitrary content to and from the DOM in the WebView.<p>Not sure about android but this is definitely possible on iOS.
评论 #14206932 未加载
评论 #14206499 未加载
m-p-3大约 8 年前
I&#x27;m honestly surprised it took them that long to abuse OAuth.