Get your own customer support community
 

Changing Password does not revoke OAuth

Changing one's password does not revoke OAuth tokens.
If I change my password at Twitter.com, malicious users who have signed in with OAuth will still have access to my account. Is this a Twitter issue or an OAuth issue?
Full report at http://shkspr.mobi/blog/?p=994
 
sad
Inappropriate?
1 person has this problem

User_default_medium