Comment by Nathanba
13 hours ago
good point, we think of these OAuth logins as so safe and yet they may be the exact opposite because it's more like logging in with your master password. I think these oauth providers like Microsoft and Google need to start mandating 2FA for every company login, it's just too dangerous otherwise.
How would 2FA help here, you'd still create the compromised OAuth credential with 2FA?