Risky Bulletin Risky Bulletin

Sponsored: Passkeys won’t stop authorisation phishing

Aug 23, 2026 · 20m

Summary

This episode explores "authorization phishing," where attackers bypass authentication controls like passkeys by exploiting OAuth flows post-login. The discussion details device code phishing, which impersonates first-party apps to grant long-lasting access, and the emerging "consent fix" technique. The guest advocates for purple teaming and browser-based security tools, like Push, to detect these sophisticated, user-interaction-heavy attacks that traditional defenses often miss.

Topics discussed

Introduction: The shift from authentication to authorization phishing Defining authorization phishing and the post-authentication threat landscape Types of authorization attacks: Consent phishing vs. Device code phishing Why device code phishing is rising and harder to defend against Mechanics of a device code phishing attack step-by-step Token privileges gained by impersonating first-party apps Legitimate use cases for device code flows in enterprise environments Defensive strategies: Purple teaming and updated security training The complexity of remediation and the emerging threat of Consent Fix How Push's browser extension provides deep visibility and detection
Listen ad-free on Castria