OAuth 2.0 is more than just a single spec and it's used to protect more than just APIs. We talk about challenges in maintaining a spec over a decade of changing technologies and new threat models. Not only can OAuth be challenging to secure by default, but it's not even always inter-operable.

Segment Resources:

Show Notes: https://securityweekly.com/asw-289

Podden och tillhörande omslagsbild på den här sidan tillhör Security Weekly. Innehållet i podden är skapat av Security Weekly och inte av, eller tillsammans med, Poddtoppen.

Application Security Weekly (Video)

OAuth 2.0 from Protecting APIs to Supporting Authorization & Authentication - Aaron Parecki - ASW #289

00:00