You're effectively talking about an attacker breaking https aren't you? Unless you can detail another way to
get at a user's token. I'm curious to hear about it.
I did, and xss and session sniffing listed on the OWASP web page, would be prevented by following OAuth flows. So that just leaves mitm, which as I said, is effectively breaking https.
Comments
You're effectively talking about an attacker breaking https aren't you? Unless you can detail another way to get at a user's token. I'm curious to hear about it.
No. There are many ways to fish bearer tokens. Encryption in transit only addresses some of them.
I'm all ears, please provide one potential way.
Just Google for session hijacking attacks. There's a wealth of information on the topic. It's a regular entry in OWASP top 10.
I did, and xss and session sniffing listed on the OWASP web page, would be prevented by following OAuth flows. So that just leaves mitm, which as I said, is effectively breaking https.
OWASP's page lists 3 more examples which it seems you omitted for some reason.