- Google Oauth currently doesn't do that
- We're doing man-in-the-middle under my proposed scenario anyway (we have to, to defeat 2FA and get a real Oauth token.) It's trivial to show the user the Google-provided image of the user's choosing.
this post was submitted on 17 Jan 2024
5 points (66.7% liked)
netsec
1313 readers
1 users here now
Technical news and discussion of information security.
Rules:
- Be excellent to each other
- Keep it on topic
- Absolutely no PII or doxing
- No disclosure posts
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments