How is oauth style authentication secure with native client apps?

Other

Archived post. New comments cannot be posted and votes cannot be cast.

Thumbnail image: Reddit, wherever you are on your AI journey, get guidance from Microsoft Security to adopt AI safely

You have to trust the client or you wouldn’t be attempting to login. Using your logic, why do you trust chrome? I assume you trust the mobile apps on your phone that you’re also logging into?

voiceless price impolite chase wine include crowd direful enjoy badge

This post was mass deleted and anonymized with Redact

More replies

If you’re just using passwords you might not know if the site where you’re entering it is legit. Use Passkeys or FIDO2 via YubiKeys

This is why you should use MFA.

It’s questions like these that make me think we’re doing a better job making technology safe than most people would have you believe. Someone like my mom should be getting hacked by things like this daily