←back to thread

193 points todsacerdoti | 1 comments | | HN request time: 0.324s | source
1. taspeotis ◴[] No.41084760[source]
> The vector here is they would use one email address to try to sign in, and a completely different email address to verify a token

Is this like the PayPal XSRF vulnerability where any issued XSRF token was considered valid regardless of the user trying to use it?

I’d expect Google to have some standard way to handle this stuff.