Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Grab it
Explore the evolution and implementation of proof of possession in OAuth 2.0 in this comprehensive conference talk from NDC Oslo 2023. Delve into the controversial decision to omit cryptographic binding of access tokens to owners in the initial OAuth 2.0 specification, and trace the decade-long journey to develop a solution. Examine the history of proof of possession, current implementation methods, and the growing demand for enhanced security features across various industries. Learn about sender constraining techniques, including OAuth Token Binding and OAuth 2.0 Mutual TLS. Gain insights into practical applications, potential drawbacks, and future developments in OAuth security. Conclude with a demo and Q&A session to solidify your understanding of this critical aspect of modern authentication protocols.
OAuth and Proof of Possession - The Long Way Round