Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Can gpgc's GitHub token be spoofed? #23

Open
wireddown opened this issue Nov 18, 2015 · 2 comments
Open

Can gpgc's GitHub token be spoofed? #23

wireddown opened this issue Nov 18, 2015 · 2 comments
Assignees

Comments

@wireddown
Copy link
Owner

Perhaps stronger protection should be added to the browser's local storage.

See http://www.martinvigo.com/even-the-lastpass-will-be-stolen-deal-with-it/

@wireddown wireddown self-assigned this Nov 18, 2015
@NonaSuomy
Copy link

Did you figure this out?

@wireddown
Copy link
Owner Author

I haven't even started looking into it. I'm not sure I have enough web or security expertise to reverse GitHub's OAuth implementation as the author did for LastPass.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants