List: websecurity@lists.webappsec.org
From: Evan Larsen
Re: [WEB SECURITY] Social login / federated identity
Sun, Feb 24, 2013 10:59 PM
. ;)
>
>
>> I think using social login is a prudent risk for most
>> websites - not online banking, sure, but most websites.
>
> Obviously I disagree.
>
> The logic of it is this; if you don't care, then you don't need to
> authenticate at all. If you do care, then do it properly.
>
> Most frameworks have it built in. Clickity-click.