We return to discussions of OAuth and all sorts of authentication. This time around we're looking at the design of authentication protocols, the kinds of trade-offs they weigh for adoption and security, and how a standard evolves over time to keep pace with new attacks and put to rest old mistakes.

Segment resources:

  • https://fusionauth.io/docs/v1/tech/core-concepts/modes
  • https://webauthn.wtf/
  • https://datatracker.ietf.org/doc/html/rfc7636
  • https://www.ietf.org/about/participate/tao/

Show Notes: https://securityweekly.com/asw-260