Auth0 Glitch Allows Attackers to Launch Phishing Attacks
threatpost.com
threatpost.com
This is Gonto. I'm the VP, Marketing and Growth at Auth0. I want to assure you that in no way is Auth0's platform insecure, or is any customer domain at risk. This is not a vulnerability, a flaw, nor is there anything to be patched. To learn more about this, please check our blog post: https://auth0.com/blog/phishing-attacks-with-auth0-facts-fir...
Thanks!
I'm genuinely curious... why is registering an account on auth0.com doesn't automatically provision it on regional sub-systems eu/au.auth0.com? Is this a common pattern with other companies in general?
"malicious-service-a.com" spoofing "service-a.com" is different than "eu.auth0.com" spoofing "au.auth0.com".
In the second case both domains are valid auth0 domains. This makes it harder for a user to detect the phishing. This seems like a legitimate concern.
Hopefully they patch it up, because I'd rather use them than rolling my own username/password, or sending my users through Facebook/Google/other sites that track you.