Why is a wildcard-subdomain callback URL in OAuth considered unsafe?

In this post: http://technotes.iangreenleaf.com/posts/closing-another-nasty-security-hole-in-oauth.html Enter your full callback URL(s) in this field. This means you should be providing the en...