simonwillison
19p4 comments posted · 0 followers · following 0
15 years ago @ materialsdave.com - Social conferencing wi... · 1 reply · +2 points
15 years ago @ Joe Gregorio | BitWorking - 140 characters isn\'t ... · 2 replies · +2 points
16 years ago @ drstarcat.com - Why an OAuth iframe is... · 1 reply · +1 points
In the long-run, the solution lies with the browsers. My browser should understand OAuth (and OpenID) and provide un-spoofable chrome confirming that I'm on the correct site.
That's another argument for sticking with the redirect though - if sites are using the redirect, browsers can start adding their own level of protection and it will Just Work with existing OAuth deployments.
16 years ago @ drstarcat.com - Why an OAuth iframe is... · 5 replies · +2 points