Security · Jul 31
Device Code Phishing Shows OAuth Login UX Is Attack Surface
A breach breakdown of a non breach: when the real authorization flow does the phishing site's costume work.
- Treat OAuth consent and device authorization prompts as attack surface, not background plumbing.
- Use conditional access and device compliance to block risky authorization attempts before users must judge them.
- Rewrite approval prompts so users can see the app, context, and risk before granting access.