YoVDO

OAuth and Proof of Possession - The Long Way Round

Offered By: NDC Conferences via YouTube

Tags

NDC Conferences Courses OAuth 2.0 Courses Mutual TLS Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the evolution and implementation of proof of possession in OAuth 2.0 in this comprehensive conference talk from NDC Oslo 2023. Delve into the controversial decision to omit cryptographic binding of access tokens to owners in the initial OAuth 2.0 specification, and trace the decade-long journey to develop a solution. Examine the history of proof of possession, current implementation methods, and the growing demand for enhanced security features across various industries. Learn about sender constraining techniques, including OAuth Token Binding and OAuth 2.0 Mutual TLS. Gain insights into practical applications, potential drawbacks, and future developments in OAuth security. Conclude with a demo and Q&A session to solidify your understanding of this critical aspect of modern authentication protocols.

Syllabus

Intro
OAuth
Proof of Possession before OAuth
OAuth 10 version 1
OAuth 10 version 2
New OAuth hashtag
The last passing gift
OAuth Proof of Possession
OAuth Token Binding
The Industry Jumps In
OAuth 20 Mutual TLS
Mutual TLS
Mutual TLS in practice
CNF token
Client certificate
Summary
Fast forwarding
Token request
Proof token
Access token
Resource access
Json token
Token hash
Demo
The downside of Depop
Questions


Taught by

NDC Conferences

Related Courses

API Testing a real web application via Postman
Coursera Project Network via Coursera
User Authentication & Authorization in Express
Codecademy
.NET Core Microservices - The Complete Guide (.NET 6 MVC)
Packt via Coursera
Add Github Login to Your Web App with OAuth 2.0
egghead.io
Getting Started with OAuth 2.0
Pluralsight