Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> it's just an access token rather than a password. The end result is the same

No, its dramatically different. If someone has my password then they have full authority over my account right up to and including changing the password itself. If they have an OAuth token they have whatever limited rights I granted to the token (could be read only, or limited to a subset of data, or automatically expiring after 24 hours).

The analogy that is often used is the special set of valet keys that come with some cars. They allow someone to drive the car - but no faster than 20mph, cannot use stereo, etc. etc.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: