They don't use https anywhere, not even on the oauth redirect back with the token in the header... isn't that.. bad?
How much you want to bet they are doing 0 encryption of the tokens they are storing on their servers.
How much you want to bet they are doing 0 encryption of the tokens they are storing on their servers.
No comments yet.