Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

OpenID Connect & OAuth 2.0 - Security Best Practices

NDC Conferences via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This course examines security best practices for OAuth 2.0 and OpenID Connect, covering common attacks, implementation pitfalls, threat models, and current countermeasures across machine-to-machine, browser-based, and interactive applications.

Syllabus

Intro
Some Context...
Simplified
Attack Model (3)
Implicit Flow Request
Implicit Flow Response
Grand Unification
Machine to Machine
Client Authentication
Sender Constrained Access Tokens w/ MTLS
Interactive Applications
Redirect URI Validation Attacks
Credential Leakage via Referrer Headers
Authorization Code Injection
Mitigation: Proof key for Code Exchange
Countermeasures Summary
Mix Up Attack (Variant 1)
Mix Up Countermeasures
How does ASP.NET Core prevent Mix Up Attacks?
Anti Pattern: Native Login Dialogs
Using a browser with Code Flow + PKCE
Different Approaches
Browser-based Applications (aka SPAs)
Anti-Forgery Protection
Refresh Token Storage in Browsers
What's next?

Taught by

NDC Conferences

Reviews

Start your review of OpenID Connect & OAuth 2.0 - Security Best Practices

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.