from Hacker News

What is real importance of the OAuth *state* parameter is?

by DBformore on 3/13/24, 10:14 PM with 2 comments

A lot of developers are not sure about the answer.

Security researchers from Salt could install malicious ChatGPT plugins, just because of a minor state mistake that ChatGPT made.

If you want to understand OAuth, this post is for you: https://salt.security/blog/security-flaws-within-chatgpt-extensions-allowed-access-to-accounts-on-third-party-websites-and-sensitive-data

  • by MorL on 3/13/24, 10:16 PM

    Could you elaborate? What do you mean by "could install malicious ChatGPT plugins" ?