To anyone who thought partial redirect URL matching in @OAuth_2 is "good enough," read this thread. Complete Periscope account takeover just by viewing a tweet. hackerone.com/reports/110293 #oauth

May 27, 2019 · 8:55 PM UTC

1
3
11
but not that tweet 😉