Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
- Greatness PhaaS just weaponized OAuth Device Auth to bypass MFA. Because apparently, "push notification" isn’t enough security theater for you. This isn’t a bug; it’s a feature for thieves who know legitimate protocols better than you do your own wallet.
Who gets hurt? Anyone relying on standard MFA without device binding. Your stack-eye won’t save you if the handshake is forged.
What to do: Stop kidding yourself with basic 2FA. Enforce hardware keys or conditional access policies that actually verify the device fingerprint. Check the seals on your auth flows. If your provider doesn’t support device-bound tokens, switch providers. We’re threadbare, but at least we don’t leave our doors unlocked for script kiddies. Relay only on my word: patch this now.