Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Save a HTTP request, and faster UX! What's not to love?

When Pinterest's new API was released, they were spewing out everything about a user to any app using their OAuth integration, including their 2FA secrets. We reported and got a bounty, but this sort of shit winds up in big companies' APIs, who really should know better.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: