Phish a device code — then watch transparency catch it
Start a device sign-in as the attacker, then see the victim screen expose WHERE it actually started.
- 1
On the Device-code phishing lab, act as the attacker: start a request with a suspicious initiator context (e.g. "attacker script, Lagos NG").
This is exactly what a real device-code phisher does: start a device authorization on THEIR OWN device/script, then get a short user_code to send you.
- 2
Switch to the victim panel, type the code, and read the approval screen before doing anything else.
A transparent screen shows WHAT is being approved and WHERE it actually started — right there next to your own account. A mismatch with your own device/location is the tell.
- 3
Tap Approve WITHOUT ticking "I started this".
It's refused (400 confirmation_required) — the explicit self-attestation is REQUIRED to approve, not just a suggestion. A phished victim who blindly taps through gets stopped here.
- 4
Tick the confirmation box and approve for real.
Approval now requires you to affirmatively assert you started this, right now, on this device — the one claim an attacker phishing you into typing their code can never truthfully make on your behalf.
Learn the theory
🩻 X-ray — what actually happened
Your own insert-only audit trail — the real server events, sanitized (never a secret), each linked to the lesson that explains it.