#oauth
Wiki 3
- don't sign in with google (the smart ape, 2026) A friend's three-year SaaS dies overnight when Google suspends his account β the thread walks through cascading SaaS lockout, four post-password-reset attack vectors, and a triage rule for when SSO is actually fine
- Google OAuth domain-takeover flaw (Truffle Security, Jan 2025) Buying a dead startup's domain for $12 lets you re-create old employee emails on Workspace and log into the dead company's Slack/Notion/Zoom via "Sign in with Google" β initially marked won't-fix, $1,337 bounty after public pressure
- OAuth token theft (multilogin + consent phishing) Two post-password-reset attack classes against Google OAuth β refresh-token replay via the undocumented multilogin endpoint, and consent phishing that asks for authorization instead of authentication. Password and 2FA changes don't stop either.