logoalt Hacker News

sneakyesterday at 5:29 PM1 replyview on HN

It's their OAuth token, it's not being stolen. It's just being copied from one place on their computer to another. This is no different than a competing browser importing your localStorage and cookies from Chrome on first launch.


Replies

NewsaHackOyesterday at 5:43 PM

No, the OAuth token is supposed to be used solely with the context of a first-party app only. Clearly, if you need to extract the key by reverse engineering or set up a proxy to spoof requests to a service, you're doing something shady.

show 1 reply