We condemn anyone that stores passwords as plaintext. Time to treat access tokens as nothing less than a password.
How would you store access tokens on a device, using two-way encryption or do you have something else in mind?
All your Facebook Access Tokens are belong to us
11–18 of 18 posts
Re: All your Facebook Access Tokens are belong to us
#12Can anyone get to the article?
Re: All your Facebook Access Tokens are belong to us
#13Re: All your Facebook Access Tokens are belong to us
#14Re: All your Facebook Access Tokens are belong to us
#15Re: All your Facebook Access Tokens are belong to us
#16Re: All your Facebook Access Tokens are belong to us
#17Can't read blog post: Error 520 Ray ID: c513da5e9750697 Web server is returning an unknown error https://support.cloudflare.com/hc/en-us/articles/200171936-E... humm...
fixed now.
Re: All your Facebook Access Tokens are belong to us
#18Earlier quoted context omitted.
but then for any reasonable application to be able to use them they'll need to store the unencryption key anyway..
Obviously you wouldn't store the encryption key in plaintext...
That's easy! We could use two-way encryption to encrypt the encryption key.