Skip to main content
OAuth

OAuth

Internet protocolWikipedia

Search complete. 404 mentions across 152 episodes found for "OAuth".

Sep 11, 2026

speaker_0HOST
3:12
This update features an interactive onboarding walkthrough, support for populating workspaces from bare repositories, and cleaner syncing between your local Git branches and Looker development mode.
speaker_0HOST
3:24
Security is also improved with OAuth support for the Curo IDE and highly secure storage of API client secrets.
speaker_0HOST
3:33
And for those using the legacy mobile app, the deprecation of the Looker mobile legacy application has been postponed to January 31st, 2027.
speaker_0HOST
3:44
So you have a little more runway to migrate to the standard non-legacy Looker mobile app.
Jenna GaidusekHOST
18:00
And so I did.
Jenna GaidusekHOST
18:01
And now they're like, oh, well, here's your OAuth right inside of your stuff.
Jenna GaidusekHOST
18:04
It's all built in.
Jenna GaidusekHOST
18:05
I'm like, oh, cool.
AndreHOST
20:43
with Strava app.
AndreHOST
20:46
So like the Garmin syncs to Strava and then Strava allows you to build OAuth based apps
speaker_2UNKNOWN
20:52
for
AndreHOST
20:52
Strava.
speaker_1HOST
48:29
Security operation centers monitor those oath consent grants very closely, because malicious apps constantly try to trick users into approving them.
speaker_1HOST
48:36
But this AI-designed toolkit avoided the OAuth flow entirely.
speaker_0HOST
48:40
How? If it didn't ask for permission, how did it get the tokens?
speaker_1HOST
48:44
By going directly to the operating system's memory.
ThanosHOST
40:44
Okay.
Michael RollinsHOST
40:46
But I guess the point being is like you can actually control that from the Gmail dashboard, from the OAuth credentials.
ThanosHOST
40:53
Well, no.
ThanosHOST
40:54
Yes, with Gmail you can, but not all products give you fine green access controls.
James MaudHOST
24:32
We have, you know, all these things that are now starting to appear that weren't in our vocabulary a few years ago around MCPs and things like that.
James MaudHOST
24:38
And I know you've discussed the challenges with MCP vendors not always following their own OAuth spec.
James MaudHOST
24:45
So could you elaborate on that and explain to listeners what the challenge is there with these MCP vendors?
Jeffrey MattsonGUEST
24:51
Yeah, well, I think probably your audience would understand what MCP is.
James MaudHOST
26:22
Yeah, I think a lot of people don't realize that, I think there was a study earlier in the year that said around 40% of remote MCP servers ship with zero authentication.
James MaudHOST
26:31
The ones that have some level will often handle credentials in plain text.
James MaudHOST
26:36
A small fraction still follow the OAuth flows, but actually when the servers are meant to validate that every token was issued for them and bind it to an aeroscope and never pass it through to an upstream service.
James MaudHOST
26:47
in practice, they don't actually implement all these things that people expect.
Robert LuceroGUEST
11:19
Authentication and who you are or what you are and authorization still are the core concepts.
Robert LuceroGUEST
11:27
We're lucky to have Aaron Parecki here at Okta who helps guide us in terms of like how we think about this within the industry space and has helped us with the OAuth spec and with MCPs.
Robert LuceroGUEST
11:41
And I think that that conversation continues to come up.
Robert LuceroGUEST
11:44
And now when you have, what I sort of see is, Agents are continuing to be similar to service accounts.
GCP Bytes

GCP Bytes

049: The Slop

Sep 11 · 1 Mention

Stephen BancroftHOST
2:46
He's got his own email address.
Stephen BancroftHOST
2:48
He's OAuthed into G Drive and Gmail.
Stephen BancroftHOST
2:52
He can send emails.
Stephen BancroftHOST
2:53
He can do the whole box and dice.
KildareGUEST
18:54
Yeah, plus
ZinGUEST
18:56
we support a single sign-on, so Apple ID, Google, OAuth, which all need to be added.
TomGUEST
19:05
We are doing our best to do it, but I'll be frank, there is concerns for account security.
TomGUEST
19:10
Like one of the things that people mention is, oh, just Mac.
Matt J.HOST
28:37
Like this evil NGINX is like a proxy that you can host another company's Okta login on your domain.
Matt J.HOST
28:45
uh steal the creds through it and it also helps the evil engine x has tools built into it to help uh grab two factor and like replay two factor stuff through it as well they're very very very very good at this part okay they like blast the company with this fake login page they get a few successes that's all they need uh they grab an octa sso login and and they're in and if you guys have ever used octa you log in it's just a bunch of sas you know portals and the one login just gets you access to all of that they at machine speed pass the oauth tokens off of all they click everything instantly and they they get all the oauth tokens they pass them to their team they have a team of people ready for this success to actually occur And they have people specialized in certain SaaS services to start exfiltrating data from that OAuth token that they get to different parts of the world.
Matt J.HOST
29:41
So you can't even really do a lot of the geo stuff that you're meant to do.
Matt J.HOST
29:44
They're very, very good.

142 more episodes mention OAuth.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.