Главная
Study mode:
on
1
Intro
2
Some Context...
3
Simplified
4
Attack Model (3)
5
Implicit Flow Request
6
Implicit Flow Response
7
Grand Unification
8
Machine to Machine
9
Client Authentication
10
Sender Constrained Access Tokens w/ MTLS
11
Interactive Applications
12
Redirect URI Validation Attacks
13
Credential Leakage via Referrer Headers
14
Authorization Code Injection
15
Mitigation: Proof key for Code Exchange
16
Countermeasures Summary
17
Mix Up Attack (Variant 1)
18
Mix Up Countermeasures
19
How does ASP.NET Core prevent Mix Up Attacks?
20
Anti Pattern: Native Login Dialogs
21
Using a browser with Code Flow + PKCE
22
Different Approaches
23
Browser-based Applications (aka SPAs)
24
Anti-Forgery Protection
25
Refresh Token Storage in Browsers
26
What's next?
Description:
Explore the security best practices for OpenID Connect and OAuth 2.0 in this comprehensive conference talk. Delve into the evolution of these protocols since their initial publication, examining how they've become the standard for API protection and the foundation of OpenID Connect. Learn about the attacks on known implementation weaknesses and anti-patterns, as well as how changing technology has expanded their usage to new use cases and higher security environments. Discover the IETF's "Best Current Practices" (BCPs) that update the original specifications and threat models, providing more prescriptive guidance. Gain insights into topics such as the simplified attack model, implicit flow, machine-to-machine communication, client authentication, and sender-constrained access tokens. Examine interactive applications, redirect URI validation attacks, credential leakage, and authorization code injection. Understand mitigation strategies like Proof Key for Code Exchange (PKCE) and countermeasures for various attacks, including the Mix Up attack. Explore anti-patterns like native login dialogs and learn about different approaches for browser-based applications. Dive into anti-forgery protection, refresh token storage in browsers, and get a glimpse of what's next in the world of OpenID Connect and OAuth 2.0 security. Read more

OpenID Connect & OAuth 2.0 - Security Best Practices

NDC Conferences
Add to list