Hackers: can you impersonate other users using javascript?
Is there protection against this on the websites?
Today, I fooled around with DISQUS and used the javascript console to try and fool it into thinking I was someone else. But I think that with DISQUS, they rely on the cookie (not the uid in javascript) when you post the comment, so you can't impersonate other users. However, if we go back to my original question -- how do websites which implement authentication with facebook, google, etc. protect against such impersonations?