A good reason not to use OAuth only accounts in your apps

rhymes - Sep 28 '18 - - Dev Community

Or at least, not to use Facebook auth.

As you probably know Facebook just disclosed a data breach of at least 50 million accounts (likely many, many, more than that).

Amid of all the info that's coming out something caught my attention:

Which reminded me of this post by @michael:

There are advantages on using OAuth delegation to login your users, unfortunately this means that if such account is breached all those apps linked to it are vulnerable.

Although I haven't seen Facebook only apps/websites in a while, if you don't really trust the login provider (who trusts Facebook nowadays?), please provide an alternative path for your users's authentication.

ps. Facebook took three days to disclose this to the public

. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
Terabox Video Player