OAuth Device Code Phishing: Azure vs. Google Compared
ID: bd98de8b-1671-5b1e-89bb-9243ff9a8029
STIX ID: report--bd98de8b-1671-5b1e-89bb-9243ff9a8029
Feed Name: Bleeping Computer
This report examines 'device code' OAuth 2.0 phishing: an attacker requests a device code from an identity provider, tricks a user into entering the code on a legitimate login page, and polls the provider to retrieve the resulting access/refresh tokens. The author shows concrete Azure examples (cURL, token polling) and explains how Microsoft’s permissive client IDs and resource scoping enable powerful post-phish primitives—up to stealing Primary Refresh Tokens—whereas Google’s device-code implementation restricts scopes (Drive/YouTube) and requires app registration/verification, greatly limiting abuse.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
