Master AI and Machine Learning: From Neural Networks to Applications
Learn AI, Data Science & Business — Earn Certificates That Get You Hired
Overview
AI, Data Science & Cloud Certificates from Google, IBM & Meta — 40% Off
One plan covers every Professional Certificate on Coursera. 40% off Coursera Plus Annual.
Unlock All Certificates
In this one-hour conference talk from NDC Security in Oslo, Norway, Philippe De Ryck explores the evolution of OAuth 2.0 security for frontend applications. Learn how OAuth 2.0 can potentially expand attack surfaces when XSS vulnerabilities exist, and discover the journey that led De Ryck to become a co-author of the "OAuth 2.0 for browser-based apps" specification. Explore the nearly finalized RFC, understand specific threats posed by XSS vulnerabilities, and examine effective security enhancement strategies. Gain practical insights into implementing the Backend-For-Frontend (BFF) approach with minimal development impact. Walk away with comprehensive knowledge of OAuth 2.0 frontend security and actionable steps to secure sensitive applications.
Syllabus
Breaking and securing OAuth 2.0 in frontends at NDC Security - Philippe De Ryck - NDC Security 2025
Taught by
NDC Conferences