Тёмный

Are You Properly Using JWTs? - Dmitry Sotnikov 

AppSec California
Подписаться 1,9 тыс.
Просмотров 1,6 тыс.
50% 1

appseccalifornia.org/
JSON Web tokens (JWTs) are used massively in API-based applications as access tokens or to transport information across services. Unfortunately, JWT are often mis-used and incorrectly handled. Massive data breaches have occurred in the last 18 months due to token leakage and lack of proper of validation.
This session focuses on best practices and real world examples of JWT usage, where we cover:
- Typical scenarios where using JWT is a good idea
- Typical scenarios where using JWT is a bad idea!
- Principles of Zero trust architecture and why you should always validate
- Best practices to thoroughly validate JWTs and potential vulnerabilities if you don’t.
- Use cases when encryption may be required for JWT
Dmitry Sotnikov
Vice President of Cloud Platform, 42Crunch
Dmitry Sotnikov serves as Vice President of Cloud Platform at 42Crunch - an enterprise API security company - and also maintains APISecurity.io, a popular community site with daily API Security news and weekly newsletter on API vulnerabilities, breaches, standards, best practices.

Наука

Опубликовано:

 

20 фев 2020

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 6   
@abbushi
@abbushi 4 года назад
Awesome session!
@sheshanandareddy7456
@sheshanandareddy7456 4 года назад
Nice Presentation. Thanks :)
@rahulmaji53
@rahulmaji53 3 года назад
Why it's not recommended to use token in web application. isn't it gonna solve CSRF attacks?
@marcinkuzniar522
@marcinkuzniar522 4 года назад
OAuth is not an standard ...
@DSotnikov
@DSotnikov 4 года назад
tools.ietf.org/html/rfc6749 ;)
@42Crunch
@42Crunch 4 года назад
See RFC6749
Далее
JWT Parkour - Louis Nyffenegger
40:34
Просмотров 2 тыс.
Я ПОКУПАЮ НОВУЮ ТАЧКУ - МЕЧТУ!
39:05
doing impossible challenges✅❓
00:25
Просмотров 7 млн
Телеграмм-Колян Карелия #юмор
00:10
OAuth 2.0 and OpenID Connect (in plain English)
1:02:17
What Is JWT and Why Should You Use JWT
14:53
Просмотров 1,1 млн
Why is JWT popular?
5:14
Просмотров 295 тыс.
Hacking Websites with SQL Injection - Computerphile
8:59
iPhone 15 Pro в реальной жизни
24:07
Просмотров 433 тыс.
$1 vs $100,000 Slow Motion Camera!
0:44
Просмотров 27 млн