DEV Community

Discussion on: A good reason not to use OAuth only accounts in your apps

Collapse
 
ben profile image
Ben Halpern

Duly noted as the webmaster of an Oauth-only app. We have good reasons for restricting to existing social profiles for spam/harassment purposes, but I think we should build the path for signing in and maintaining accounts via email/password.

Collapse
 
erebos-manannan profile image
Erebos Manannán

How about "simply" social + 2FA? Google Authenticator & Yubikey ftw.