OAuth
Internet protocolWikipedia
404
MENTIONS
152
EPISODES
121
PODCASTS
Search complete. 404 mentions across 152 episodes found for "OAuth".
Sep 11, 2026
September 11th 2026 - Google Cloud Update
S
3:12speaker_0HOST
This update features an interactive onboarding walkthrough, support for populating workspaces from bare repositories, and cleaner syncing between your local Git branches and Looker development mode.
S
3:24speaker_0HOST
Security is also improved with OAuth support for the Curo IDE and highly secure storage of API client secrets.
S
3:33speaker_0HOST
And for those using the legacy mobile app, the deprecation of the Looker mobile legacy application has been postponed to January 31st, 2027.
S
3:44speaker_0HOST
So you have a little more runway to migrate to the standard non-legacy Looker mobile app.
Ep 77: The AI Conversation No One Wants to Have
J
18:00Jenna GaidusekHOST
And so I did.
J
18:01Jenna GaidusekHOST
And now they're like, oh, well, here's your OAuth right inside of your stuff.
J
18:04Jenna GaidusekHOST
It's all built in.
J
18:05Jenna GaidusekHOST
I'm like, oh, cool.
#106 - When Your Pet Project Tells You No
A
20:43AndreHOST
with Strava app.
A
20:46AndreHOST
So like the Garmin syncs to Strava and then Strava allows you to build OAuth based apps
S
20:52speaker_2UNKNOWN
for
A
20:52AndreHOST
Strava.
Detecting and Countering AI Misuse: September 2026 Report
S
48:29speaker_1HOST
Security operation centers monitor those oath consent grants very closely, because malicious apps constantly try to trick users into approving them.
S
48:36speaker_1HOST
But this AI-designed toolkit avoided the OAuth flow entirely.
S
48:40speaker_0HOST
How? If it didn't ask for permission, how did it get the tokens?
S
48:44speaker_1HOST
By going directly to the operating system's memory.
Nobody Knows How to Stop This
T
40:44ThanosHOST
Okay.
M
40:46Michael RollinsHOST
But I guess the point being is like you can actually control that from the Gmail dashboard, from the OAuth credentials.
T
40:53ThanosHOST
Well, no.
T
40:54ThanosHOST
Yes, with Gmail you can, but not all products give you fine green access controls.
Ep. 109 – Dealing with Vibe Coding Execs // Geoffrey Mattson
J
24:32James MaudHOST
We have, you know, all these things that are now starting to appear that weren't in our vocabulary a few years ago around MCPs and things like that.
J
24:38James MaudHOST
And I know you've discussed the challenges with MCP vendors not always following their own OAuth spec.
J
24:45James MaudHOST
So could you elaborate on that and explain to listeners what the challenge is there with these MCP vendors?
J
24:51Jeffrey MattsonGUEST
Yeah, well, I think probably your audience would understand what MCP is.
J
26:22James MaudHOST
Yeah, I think a lot of people don't realize that, I think there was a study earlier in the year that said around 40% of remote MCP servers ship with zero authentication.
J
26:31James MaudHOST
The ones that have some level will often handle credentials in plain text.
J
26:36James MaudHOST
A small fraction still follow the OAuth flows, but actually when the servers are meant to validate that every token was issued for them and bind it to an aeroscope and never pass it through to an upstream service.
J
26:47James MaudHOST
in practice, they don't actually implement all these things that people expect.
How Okta sets guardrails and context for AI agents
R
11:19Robert LuceroGUEST
Authentication and who you are or what you are and authorization still are the core concepts.
R
11:27Robert LuceroGUEST
We're lucky to have Aaron Parecki here at Okta who helps guide us in terms of like how we think about this within the industry space and has helped us with the OAuth spec and with MCPs.
R
11:41Robert LuceroGUEST
And I think that that conversation continues to come up.
R
11:44Robert LuceroGUEST
And now when you have, what I sort of see is, Agents are continuing to be similar to service accounts.
049: The Slop
S
2:46Stephen BancroftHOST
He's got his own email address.
S
2:48Stephen BancroftHOST
He's OAuthed into G Drive and Gmail.
S
2:52Stephen BancroftHOST
He can send emails.
S
2:53Stephen BancroftHOST
He can do the whole box and dice.
Pixel Starships Space Strategy Game September AMA
K
18:54KildareGUEST
Yeah, plus
Z
18:56ZinGUEST
we support a single sign-on, so Apple ID, Google, OAuth, which all need to be added.
T
19:05TomGUEST
We are doing our best to do it, but I'll be frank, there is concerns for account security.
T
19:10TomGUEST
Like one of the things that people mention is, oh, just Mac.
153 Million Driver's Licenses Stolen, Nigerian Sextortion Rings, and Team PCP's OPSEC Failure
M
28:37Matt J.HOST
Like this evil NGINX is like a proxy that you can host another company's Okta login on your domain.
M
28:45Matt J.HOST
uh steal the creds through it and it also helps the evil engine x has tools built into it to help uh grab two factor and like replay two factor stuff through it as well they're very very very very good at this part okay they like blast the company with this fake login page they get a few successes that's all they need uh they grab an octa sso login and and they're in and if you guys have ever used octa you log in it's just a bunch of sas you know portals and the one login just gets you access to all of that they at machine speed pass the oauth tokens off of all they click everything instantly and they they get all the oauth tokens they pass them to their team they have a team of people ready for this success to actually occur And they have people specialized in certain SaaS services to start exfiltrating data from that OAuth token that they get to different parts of the world.
M
29:41Matt J.HOST
So you can't even really do a lot of the geo stuff that you're meant to do.
M
29:44Matt J.HOST
They're very, very good.
142 more episodes mention OAuth.
Create an account to see the whole feed, search across every transcript, and follow the entities you care about.