I wrote something: "Does OAuth2 have a usability problem? (yes!)"

evertpot.com/oauth2-usability/

Hackernews post: news.ycombinator.com/item?id=3