logo

DPoP and the Burden of Proof: Negating the Threat of Stolen OAuth Tokens

Conference:  RSA Conference 2023

2023-04-24

Authors:   Brian Campbell


Abstract

A personal account of the rich and sometimes troubled history of proof-of-possession tokens in OAuth with a focus on DPoP—our last best hope for strong cryptographic defenses against the use of stolen tokens. Tokens which, as mostly bearer tokens today, are an increasingly attractive target to adversaries as user credentials themselves become harder to compromise with MFA/FIDO/etc.

Materials:

Tags:

Post a comment