You Shall Not Password: Modern Authentication for Web Apps - Eli Holderness - NDC London 2022

  Рет қаралды 4,467

NDC Conferences

NDC Conferences

Күн бұрын

In the good old days, your users would log into a web app with a username and password. But now people expect an alphabet soup of SSO, 2FA, OAuth, OIDC, SAML, FIDO2, OTP... What do they all mean - and why do they matter? Why is central authentication useful? What does two-factor authentication really protect us from, and what's still wide open? Learn how to keep your users safe as we discuss the good, the bad and the ugly of modern authentication mechanisms for the Web.
This talk is aimed at anyone passingly familiar with web development, with an interest in security, or who simply wants to know what’s really going on when you ‘sign in with Google’.
Check out more of our featured speakers and talks at
www.ndcconfere...
ndclondon.com/

Пікірлер: 10
@12q8
@12q8 2 жыл бұрын
Oh it's not even just relaying on the telecom company's security. If someone has the id for your sim card, there are devices that can overwrite any simcard with your id without the telecom knowledge.
@jcsantosbr
@jcsantosbr 2 жыл бұрын
Great talk with clean information and explanations!
@12q8
@12q8 2 жыл бұрын
We have something similar to the sigle sign-on at the place I work at. We use Jira and other similar platforms, but the way they make it work is basically having everything on-premise, maintained by the company, in a local network.
@capability-snob
@capability-snob 2 жыл бұрын
Humans make poor containers for arbitrary byte strings. Here's hoping we can stop using identity in access control decisions at all. Object-capability theory, a model not unlike the "magic link" system described here, is already the way we build high assurance systems outside of the web and is easier to use too. Hopefully we can fix the last mile of browser support for capabilities in the coming years.
@phizc
@phizc 2 жыл бұрын
Do I have to pay someone, e.g. Google, if I want to use OpenID Connect on a website or app? If so, what does it cost?
@joshuajones4482
@joshuajones4482 2 жыл бұрын
Please do not hash passwords for storage by simply applying a cryptographic hashing function to the raw password string concatenated with a salt string, as that construction is vulnerable to a couple of different kinds of attacks. Also, definitely do not store the salt value along with the password hash as this allows malicious entities to take advantage of length extension attacks, rendering the salt effectively useless. Instead, you should use an HMAC and ensure that the key is not stored alongside the produced hash digest.
@kibe2134
@kibe2134 2 жыл бұрын
The way you say "stuff" scares me a bitm
@12q8
@12q8 2 жыл бұрын
What about a synced password manager? Something synced on my PC and whatever other devices I have?
@andrewreiser3584
@andrewreiser3584 2 жыл бұрын
This was a pretty poor talk. Just vague descriptions of stuff. Who was this for, anyway? Project managers and business analysts? Certainly not devs.
@12q8
@12q8 2 жыл бұрын
This is great, but seems rudimentary. I wonder if perhaps there is a way to make this as seamless as possible in the future.
Where’s C# headed? - Mads Torgersen - NDC Copenhagen 2022
1:01:28
NDC Conferences
Рет қаралды 29 М.
Back to Basics: Efficient Async and Await - Filip Ekberg - NDC London 2022
1:01:59
GIANT Gummy Worm Pt.6 #shorts
00:46
Mr DegrEE
Рет қаралды 89 МЛН
SHAPALAQ 6 серия / 3 часть #aminkavitaminka #aminak #aminokka #расулшоу
00:59
Аминка Витаминка
Рет қаралды 1,7 МЛН
Minecraft Creeper Family is back! #minecraft #funny #memes
00:26
Ozoda - Lada (Official Music Video)
06:07
Ozoda
Рет қаралды 12 МЛН
OAuth - the good Parts - Dominick Baier - NDC Porto 2022
57:50
NDC Conferences
Рет қаралды 10 М.
Realtime Chat App in React Native and AWS (Backend) 🔴
3:29:01
notJust․dev
Рет қаралды 141 М.
Developing for Linux on Windows - Scott Hanselman - NDC Porto 2022
1:08:42
Back to Basics: Efficient Async and Await - Filip Ekberg - NDC Porto 2022
1:02:00
Demystifying Azure AD, JWTs & OIDC - Graeme Foster - NDC Melbourne 2022
1:01:48
OAuth 2.0 and OpenID Connect (in plain English)
1:02:17
OktaDev
Рет қаралды 1,7 МЛН
GIANT Gummy Worm Pt.6 #shorts
00:46
Mr DegrEE
Рет қаралды 89 МЛН