accountless.eth
@accountless.eth
"Here’s the issue: If a service (e.g., Slack) relies solely on these two claims, ownership changes to the domain won’t look any different to Slack. When someone buys the domain of a defunct company, they inherit the same claims, granting them access to old employee accounts."
1 reply
0 recast
1 reaction
accountless.eth
@accountless.eth
https://trufflesecurity.com/blog/millions-at-risk-due-to-google-s-oauth-flaw
1 reply
0 recast
0 reaction