Program Sikkerhetsfestivalen 2026

Offensive Security

Delegating your attack surface through OAuth consents

Onsdag 1 · Frimurerlosjen, rom 2

EnglishDetailed 40 min

Christian August Holm Hansen

Christian August Holm Hansen

Security specialist @ Binary Security AS

Christian August Holm Hansen is the co-founder of Binary Security, a consulting agency focusing on penetration testing, application- and cloud security. He has worked in offensive security since 2015 and done cloud security research and bug bounty on Google Cloud Platform since 2017. In recent years, he has focused more on Azure cloud research and was awarded the Microsoft MVR (Most Valuable Researcher) for 2025.

OAuth consents have become a daily chore for most of us. We all know about consent phishing, but what about the case where the OAuth client is legitimate, comes from a trusted provider, and has already been granted access to your resources?

Developers, admins, and security professionals normally focus on what we can control: the hardening of our Identity Providers and Resource Servers. However, the moment a user or admin clicks "Accept" on a third-party integration, the attack surface is effectively increased to include that third party, a black box of code, infrastructure, and governance which we have zero control over. In this session, we will dive into how this trust can be abused to compromise apps and organizations and how to limit it for your own resources.

We will demonstrate some examples from Entra ID and Google that basically delegate top-tier admin roles to third parties. This is not an edge case as we see it in virtually all organizations we work with. As for application-specific vulnerabilities, we will show practical examples from bug bounty findings at Google, demonstrating how I could steal all your spreadsheets if you consented to a first-party Google OAuth client.

  1. Building TPT: From alert chaos to clear priorities 1 · Frimurerlosjen, rom 1
  2. Cryptanalysis with Claude Code 10 · HeartBox ,Teatersalen
  3. Your Source Code Is Under Attack. Who’s Defending It? 10 · HeartBox, Byscenen
  4. Risiko med to briller: FRIA og DPIA i KI-prosjekter 11- Breiseth, Storlon
  5. GenAI in the War Room: Crafting, Facilitating, and Analyzing OT Tabletops 2 · Home hotel Hammer, moen nede
  6. Lykketiøringen som forsvant: En leksjon i strategisk blindhet og grå nesehorn. 2 · Home hotel Hammer, moen oppe
  7. Bry deg! Hvorfor arbeidsmiljø er et av våre viktigste tiltak 3 · Hvelvet, Gullsalen
  8. Når leverandøren blir angrepet – hvem tar regningen? 4 · Kommunestyresalen, Lillehammer rådhus
  9. Virksomhetslommebok – hva er det? 5 · Kulturhuset Banken, Expedisjon
  10. When freedom is at stake - from Ukraine's frontline to Norwegian preparedness 5 · Kulturhuset Banken, Festsalen
  11. Minimum Viable Company - Når alt står på spill: Hva er det viktigste? 5 · Kulturhuset Banken, Holbøsalen
  12. Reducing business risk through proactive digital forensics 5 · Kulturhuset Banken, Kafeen
  13. Steering the AI Revolution: Building Trust and Accountability with AI Governance 6 · Lillehammer kino, sal 2
  14. Cybersikkerhet er også kultur: Empiriske funn om nasjonale forskjeller 6 · Lillehammer kino, sal 4
  15. Hunting international cyber criminals 9 · Victoria Scandic, sal 1+2
  16. AI i SOC-en: hva vi lærte av å bygge en agentisk triage-assistent 9 · Victoria Scandic, sal 3