Hacker News new | past | comments | ask | show | jobs | submit login

How does this work with third party login? For instance I can use my github accout to log in to gitlab. Seems like a security risk for even dormant accounts.

I'd assume that any use of github services (such as use of a token) keeps the account non dormant.

I'd imagine all OAuth tokens associated with an account are rolled when it's transferred.

I was not clear, github works as an identity provider. I am not talking about api access to github, I am talking about using github to log into other services.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
