Loading…
SecAppDev 2019 has ended
Friday, February 22 • 14:00 - 15:30
The parts of JWT security nobody talks about

Sign up or log in to save this to your schedule and see who's attending!

At the surface, JWTs look simple. In this session, we dig deeper into the security properties of JWTs. We look at common misconceptions and mistakes. We also look at advanced features, such as encryption.

Abstract
JSON Web Tokens (JWT) have become the de facto standard to transfer application claims between the client and the server. By design, they incorporate the use of signatures to ensure the integrity of the data. However, merely signing the data alone is not enough to guarantee security.

In this talk, we zoom into the security properties of JWTs. After introducing the different signature schemes, we dive into the hard parts nobody talks about. How do you manage and identify the keys used for the signature? How do you handle key rotation? And what about encrypting JWTs? This talk answers all these questions. You will walk away with a set of best practices for adequately securing JWTs.

This session is intended for anyone building, designing or securing web applications

Speakers
PD

Philippe De Ryck

Founder, Pragmatic Web Security


Friday February 22, 2019 14:00 - 15:30
West wing (room Lemaître)