Posts
Media
Videos
Starter Packs
Aaron Parecki
@aaronpk.com
· 21h
Aaron Parecki
@aaronpk.com
· 21h
Aaron Parecki
@aaronpk.com
· 21h
Aaron Parecki
@aaronpk.com
· 23h
Aaron Parecki
@aaronpk.com
· 10d
Aaron Parecki
@aaronpk.com
· 22d
Aaron Parecki
@aaronpk.com
· 22d
Aaron Parecki
@aaronpk.com
· 22d
DPoP for the OAuth 2.0 Device Authorization Grant
The OAuth 2.0 Device Authorization Grant [RFC8628] is an authorization flow for devices with limited input capabilities. Demonstrating Proof of Possession (DPoP) [RFC9449] is a mechanism to sender-con...
datatracker.ietf.org
Aaron Parecki
@aaronpk.com
· 22d
DPoP for the OAuth 2.0 Device Authorization Grant
The OAuth 2.0 Device Authorization Grant [RFC8628] is an authorization flow for devices with limited input capabilities. Demonstrating Proof of Possession (DPoP) [RFC9449] is a mechanism to sender-con...
datatracker.ietf.org
Aaron Parecki
@aaronpk.com
· 23d
Cross-Device Flows: Security Best Current Practice
This document describes threats against cross-device flows
along with practical mitigations, protocol selection guidance,
and a summary of formal analysis results identified as relevant to
the securit...
www.ietf.org
Aaron Parecki
@aaronpk.com
· 23d
RFC 9449: OAuth 2.0 Demonstrating Proof of Possession (DPoP)
This document describes a mechanism for sender-constraining OAuth 2.0 tokens via a proof-of-possession mechanism on the application level. This mechanism allows for the detection of replay attacks wit...
datatracker.ietf.org
Aaron Parecki
@aaronpk.com
· 23d
Aaron Parecki
@aaronpk.com
· Aug 6
Aaron Parecki
@aaronpk.com
· Aug 5
Aaron Parecki
@aaronpk.com
· Aug 5
Aaron Parecki
@aaronpk.com
· Aug 5