Here's my step by step guide for how (and why) to leave Facebook without actually deleting your account. I did this in June and haven't looked back. #DeleteFacebookaaronparecki.com/2020/06/14/…
The main threat is token scanning attacks, but there isn't much difference between scanning the introspection endpoint or a resource server at that point. That said, the introspection endpoint is supposed to require authentication according to tools.ietf.org/html/rfc7662#…
Over the last year, I've helped thousands of software developers learn about web security and OAuth by hosting live and virtual workshops, and all this knowledge is now available as an on-demand video course!
📺 ➡ oauth.wtf/course