Yes, this is the story. Sorry for including the wrong link.

We can find out what the issue was but that wasn't necessarily my point.

The problem is that there is unfortunately little understanding about
the different layers and responsibilities involved. I think there is
something to write about and I will compile a first draft.


On 12/01/2014 06:51 PM, John Bradley wrote:
> Hannes,
> I think this may be the link you were trying to share.
> I suspect the problem was the profile ID leaking via a ad rather than 
> anything to do with OAuth
> as she never logged in.  
> John B.
>> On Dec 1, 2014, at 1:25 PM, Hannes Tschofenig <> 
>> wrote:
>> Hi all,
>> I fear we have to write another article to clarify what OAuth does and
>> what it does not do based on the misinformation spread with this recent
>> article:
>> A quote from that article:
>> "
>> Graham Williams, a Vancouver-based technology expert, points to what is
>> known as an "open authentication protocol" — or OAuth — where people
>> often unwittingly share personal information with third-party websites.
>> "
>> Ciao
>> Hannes
>> _______________________________________________
>> OAuth mailing list

Attachment: signature.asc
Description: OpenPGP digital signature

OAuth mailing list

Reply via email to