OAuth consent is not proof of identity
Clicking "allow" gives an application access. It does not verify anything about that application.
The consent screen is genuine and comes from a service you trust, which is exactly why consent phishing works. The screen is telling you what permissions are being requested, not whether the requester deserves them. Reading what is actually being asked for, rather than whose logo is at the top, is the part people skip.
More on OAuth and federation
- Token scope defines capabilityIt only presses three
- Bearer tokens behave like cashWhoever picks it up
- SSO concentrates convenience and consequenceOne handle, every gate
- Federation shifts where trust livesThe decision moved house
- Redirect URI validation protects token deliveryPosted only where it fits
- Token audience prevents universal reuseA ticket for this gate only
