back

by DemiGuru·3y ago·view on hn ↗
What I think you're missing is the possibility of using these tokens as an attack vector in this case - social engineering. Impersonating a senior manager or a C level entity. So while on the surface you can say that the risk is minimal this can be damaging to a business provided you impersonate the "right" person.
1 comments
I'm not saying it's not a big deal if those tokens get stolen. I'm saying that if your tokens could get stolen this way, they could get stolen a different way even if they weren't stored in cleartext like this.