SecAppDev 2019 has ended
Back To Schedule
Friday, February 22 • 14:00 - 15:30
The parts of JWT security nobody talks about

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

At the surface, JWTs look simple. In this session, we dig deeper into the security properties of JWTs. We look at common misconceptions and mistakes. We also look at advanced features, such as encryption.

JSON Web Tokens (JWT) have become the de facto standard to transfer application claims between the client and the server. By design, they incorporate the use of signatures to ensure the integrity of the data. However, merely signing the data alone is not enough to guarantee security.

In this talk, we zoom into the security properties of JWTs. After introducing the different signature schemes, we dive into the hard parts nobody talks about. How do you manage and identify the keys used for the signature? How do you handle key rotation? And what about encrypting JWTs? This talk answers all these questions. You will walk away with a set of best practices for adequately securing JWTs.

This session is intended for anyone building, designing or securing web applications


Philippe De Ryck

Founder, Pragmatic Web Security

Friday February 22, 2019 14:00 - 15:30 CET
West wing (room Lemaître)