Ethan Heilman · @ethan_heilman
216 followers · 258 posts · Server hexagon.space

Just dropped our paper on eprint: OpenPubkey

adds user-held public keys into OpenID Connect without breaking compatibility. This means users can create digital signatures on the web that are associated with their ID Tokens. Fully signed APIs here we come.

Our protocol is so compatible with existing IDPs that not only have we been using it in production with Google, Okta, and Microsoft IDPs for over a year, but that IDPs can't even tell that OpenPubkey is being used!

eprint.iacr.org/2023/296.pdf

#openpubkey #OIDC #json #jws #websec

Last updated 2 years ago

· @twitter
1 followers · 39244 posts · Server mstdn.skullb0x.io

Referenced link: cs.co/90013icSc
Originally posted by Duo Security / @duosec@twitter.com: twitter.com/duosec/status/1622

You want to enable users to sign on to everything. That's why we're excited that Duo SSO support for apps is in GA 🙌 Learn how you can help your users seamlessly connect to all their apps: cs.co/90013icSc

#SSO #OIDC #CiscoLiveEMEA

Last updated 2 years ago

Ethan Heilman · @ethan_heilman
176 followers · 137 posts · Server hexagon.space

What's the best OpenID Connect podcast out there?

#infosec #OIDC

Last updated 2 years ago

· @twitter
1 followers · 28011 posts · Server mstdn.skullb0x.io

Referenced link: cs.co/9009MhE4L
Originally posted by Duo Security / @duosec@twitter.com: twitter.com/duosec/status/1598

We know you have applications to protect 📱 So we're excited to announce that support in Duo is now in early access. Learn more in our latest blog: cs.co/9009MhE4L

#OIDC #SSO

Last updated 2 years ago

Ethan Heilman · @ethan_heilman
55 followers · 58 posts · Server hexagon.space

In the OpenID Connect spec they call the case in which an ID Token has only one audience in its 'aud' claim "the common special case". Which sounds like they expect most people to have one audience but they want to treat the default behavior as a special case, odd.

#OIDC

Last updated 2 years ago

Ethan Heilman · @ethan_heilman
55 followers · 57 posts · Server hexagon.space

Going to posting a survey thread on Mastodon of OpenIDConnect attacks and defenses on Sunday. I've reading RFCs all these week.

I want to make sure I don't miss anything good, send me top shelf /OAuth attacks

#OIDC

Last updated 2 years ago

Jan Veen ❌ · @F1rst_Unicorn
16 followers · 928 posts · Server mastodon.3fx.ch

Sich bei vielen Diensten mit einem Account und idealerweise U2F einloggen zu können benötigt so viel Zeit, man muss es schon ein Hobby nennen

#SSO #OIDC #U2F

Last updated 4 years ago