Systematically Breaking and Fixing OpenID Connect

Systematically Breaking and Fixing OpenID Connect

OWASP Foundation via YouTube Direct link

Introduction

1 of 32

1 of 32

Introduction

Class Central Classrooms beta

YouTube playlists curated by Class Central.

Classroom Contents

Systematically Breaking and Fixing OpenID Connect

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Introduction
  2. 2 Three simple questions
  3. 3 The plan
  4. 4 OAuth vs OpenID Connect
  5. 5 OpenID Connect
  6. 6 Three parties
  7. 7 This face
  8. 8 Dynamic solution
  9. 9 ID token
  10. 10 Parameters
  11. 11 Attacks
  12. 12 Threat Model
  13. 13 Categories
  14. 14 Attacker Identity Provider
  15. 15 Single Phase Attacks
  16. 16 Another Attack
  17. 17 Replay Attacks
  18. 18 Supported Values
  19. 19 Singlephase attacks
  20. 20 Crossphase attacks
  21. 21 Endpoints
  22. 22 IDP Confusion Attack
  23. 23 Countermeasure
  24. 24 Malicious Endpoint Attacks
  25. 25 Out of Service
  26. 26 Demo
  27. 27 Professors
  28. 28 Tobias works
  29. 29 IDPs
  30. 30 Switch
  31. 31 Current State
  32. 32 Summary

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.