Slide 17 of 28
Part 3 · Attack ScenariosSlide 17
Slide 17 · The Pattern
It's always the same three failures.
Across every scenario, authentication broke in one of three ways.
The Three Failure Modes
1. The credential check was bypassable — rate limits evaded, lockout missing, batching exploited
2. The token was stealable or forgeable — OAuth redirect flaws, tokens in URLs, JWT signature not verified
3. No credential required at all — endpoint open with no auth, internal service trusted without verification
Matched to the Scenarios
GraphQL batching → credential check bypassable
Email change without re-auth → token stealable + no re-verification
Parler → no credential required at all
Fortnite → token stealable via OAuth redirect flaw
Spotify → credential check bypassable (no rate limit)
The Root Cause

In every case, authentication was treated as a one-time gate rather than a continuous guarantee. The system checked identity once — at login — and assumed the result would stay valid forever, under all conditions, for all operations.

Secure authentication isn't a gate. It's a continuous contract that must be enforced at every layer.

← Back How do we fix it? →