Sponsored: Passkeys won’t stop authorisation phishing
Aug 23, 2026 · 20m
Summary
This episode explores "authorization phishing," where attackers bypass authentication controls like passkeys by exploiting OAuth flows post-login. The discussion details device code phishing, which impersonates first-party apps to grant long-lasting access, and the emerging "consent fix" technique. The guest advocates for purple teaming and browser-based security tools, like Push, to detect these sophisticated, user-interaction-heavy attacks that traditional defenses often miss.
Topics discussed
Introduction: The shift from authentication to authorization phishing
Defining authorization phishing and the post-authentication threat landscape
Types of authorization attacks: Consent phishing vs. Device code phishing
Why device code phishing is rising and harder to defend against
Mechanics of a device code phishing attack step-by-step
Token privileges gained by impersonating first-party apps
Legitimate use cases for device code flows in enterprise environments
Defensive strategies: Purple teaming and updated security training
The complexity of remediation and the emerging threat of Consent Fix
How Push's browser extension provides deep visibility and detection
Listen ad-free on Castria