Skip to content

Why isn't it safe to link account? #150

Answered by Benehiko
itaied246 asked this question in Q&A
Discussion options

You must be logged in to vote

Hi @itaied246

The principle is that we wouldn't know if the 3rd party social provider does email verification or not. I think with automatic account linking you can never assume it is truly safe. I suppose even with email verification, a scenario could be an account is taken over on the social provider side. Even with initial verification, on a stolen dormant account the attacker could also do account takeover with the stolen social account.

Without automatic linking they would somehow need to compromise your account at Ory first and then link the stolen social account - which doesn't make sense since stealing the account was the goal in the first place :)

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by vinckr
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants