Crumbling the Cookie Fixing a Weak Link in Authentication on the Web

  Рет қаралды 48

Identiverse - A CRA Resource

Identiverse - A CRA Resource

21 күн бұрын

Speaker: Zachary Voase - Senior Security Software Engineer - Netflix
Date: Thursday, June 1, 2023
Location: ARIA Resort & Casino | Las Vegas, NV
#identiverse2023
identiverse.com
Description: WebAuthn, OAuth 2.0, passkeys, ... the list goes on. We've never had so many tools to securely establish user and application identity while maintaining privacy and convenience. But we risk turning back the clock and squandering those gains when we tie it all together with a session identifier or simple JWT stored in a cookie. Still, browsers and HTTP clients offer few other options for securely proving identity over the course of a browsing session. In this talk we'll go over the issues that cookies and bearer tokens present, detail some application-level mitigations, and address ongoing developments in browser- and protocol-level standards to fill this gap in our industrywide security posture.

Пікірлер
Ceremonies
25:51
Identiverse - A CRA Resource
Рет қаралды 31
HTTPS, SSL, TLS & Certificate Authority Explained
43:29
Laith Academy
Рет қаралды 70 М.
Final muy increíble 😱
00:46
Juan De Dios Pantoja 2
Рет қаралды 48 МЛН
КАРМАНЧИК 2 СЕЗОН 7 СЕРИЯ ФИНАЛ
21:37
Inter Production
Рет қаралды 506 М.
Vivaan  Tanya once again pranked Papa 🤣😇🤣
00:10
seema lamba
Рет қаралды 31 МЛН
Heartwarming: Stranger Saves Puppy from Hot Car #shorts
00:22
Fabiosa Best Lifehacks
Рет қаралды 19 МЛН
Zero Trust Architecture for B2C Identity at General Motors
26:49
Identiverse - A CRA Resource
Рет қаралды 54
The walt.id Compliance Service (VCs) | Demo
1:51
walt_id
Рет қаралды 53
The Laws of Identity in the Era of Ubiquitous Identity
50:11
Identiverse - A CRA Resource
Рет қаралды 42
The Only Unbreakable Law
53:25
Molly Rocket
Рет қаралды 318 М.
OAuth 2.0 and OpenID Connect (in plain English)
1:02:17
OktaDev
Рет қаралды 1,7 МЛН
Building Radiant AI: Lessons Learned on Applying Large Language Models in Identity
48:36
Beyond Trust Presents the 2023 Microsoft Vulnerabilities Report - Dissected
24:41
Identiverse - A CRA Resource
Рет қаралды 21
ChatGPT Just Learned To Fix Itself!
5:47
Two Minute Papers
Рет қаралды 96 М.
Linux on Windows......Windows on Linux
23:54
NetworkChuck
Рет қаралды 204 М.
Мой инст: denkiselef. Как забрать телефон через экран.
0:54
ПОКУПКА ТЕЛЕФОНА С АВИТО?🤭
1:00
Корнеич
Рет қаралды 3,6 МЛН
Спутниковый телефон #обзор #товары
0:35
Product show
Рет қаралды 2,1 МЛН
Simple maintenance. #leddisplay #ledscreen #ledwall #ledmodule #ledinstallation
0:19
LED Screen Factory-EagerLED
Рет қаралды 23 МЛН
Как слушать музыку с помощью чека?
0:36