DPoP and the Burden of Proof: Negating the Threat of Stolen OAuth Tokens


Posted on in Presentations

A personal account of the rich and sometimes troubled history of proof-of-possession tokens in OAuth with a focus on DPoP—our last best hope for strong cryptographic defenses against the use of stolen tokens. Tokens which, as mostly bearer tokens today, are an increasingly attractive target to adversaries as user credentials themselves become harder to compromise with MFA/FIDO/etc.

Access This and Other RSAC Conference Presentations with Your Free RSAC Membership

Your RSAC Membership also includes AI-powered summaries, mind maps, and slides for Conference presentations, Group Discussions with experts, and more.

Watch Now >>
Participants
Brian Campbell

Speaker

Distinguished Engineer, Ping Identity


Share With Your Community