讨论OAuth泄漏责任归属及工程实践问题
Fair point from Zach that in the case of OAuth, if these leak, the impact can be hard to tell as the vendor.
Other points still stand: no single individual taking responsiblity; removing certifications; no postmortem shared are all red flags
Other points still stand: no single individual taking responsiblity; removing certifications; no postmortem shared are all red flags
@GergelyOrosz 稍微辩护一下:我不太了解 Google 生态系统,但对于 Microsoft 应用程序,应用所有者无法获取审计日志,只有客户能(有一些很好的理由说明为什么这样,但也有很好的理由说明应该反过来)。