The recent Heartbleed scare caused a huge stir, even though it was effectively fixed before it even happened. There are other sorts of security hole, however, which cant be plugged so readily, and which affected companies therefore have less incentive to publicize. A researcher in Singapore, Wang Jing, claims to have uncovered a potentially serious example of this, involving the widely-used login services OAuth and OpenID.