OAuth & OpenID Connect
Facebook Twitter LinkedIn

OAuth 2.0 Security Reinforced

Combined Session
Thursday, May 16, 2019 12:00—13:00
Location: AMMERSEE I

The OAuth working group recently decided to discourage use of the implicit grant. But that’s just the most prominent recommendation the working group is about to publish in the upcoming OAuth 2.0 Security Best Current Best Practice (https://tools.ietf.org/html/draft-ietf-oauth-security-topics), which will elevate OAuth security to the next level. The code flow shall be used with PKCE only and tokens should be sender constraint to just mention a few. Development of this enhanced recommendations was driven by several factors, including experiences gathered in the field, security research results, the increased dynamics and sensitivity of the use cases OAuth is used protect and technological changes. This session will present the new security recommendations in detail along with the underlying rationales.
Key takeaways:

OAuth 2.0 Security Reinforced
Presentation deck
OAuth 2.0 Security Reinforced
Click here to download the slide deck. Please note that downloads are only available for event participants and subscribers. You'll need to log in to download it.
Dr. Torsten Lodderstedt
Dr. Torsten Lodderstedt
yes IDP GmbH
Dr.-Ing. Torsten Lodderstedt is managing director at yes with more than 15 years experience in running large scale consumer identity services. In his previous positions, he helped organisations in...
Subscribe for updates
Please provide your email address