"if you authenticate users with Facebook it means any XSS on your website can steal User's account" #oauth2 http://homakov.blogspot.de/2013/02/hacking-facebook-with-oauth2-and-chrome.html