webauth:sec10.pdf
pdos.csail.mit.edu · 7,003 words · saved by 1 readers
N/A
Dos and Don’ts of Client Authentication on the Web Kevin Fu, Emil Sit, Kendra Smith, Nick Feamster fubob, sit, kendras, feamster @mit.edu MIT Laboratory for Computer Science http://cookies.lcs.mit.edu/ Abstract the client authentication of two systems, gained…
saved by
related reading
- passwords - Demystifying Web Authentication (Stateless Session Cookies) - Information Security Stack Exchangesecurity.stackexchange.com
- JWT should not be your default for sessionsevertpot.com
- Why We Don’t Trust the Database With Authentication – Sturdy Statisticsblog.sturdystatistics.com
- Discovering cryptographic weaknesses with Claude \ Anthropicanthropic.com
- 297.pdfeprint.iacr.org
- Part 2: Complete User Authentication: Sessions vs JWT | by Nick Jagodzinski | Mediummedium.com
- What is Private Key JWT: Deep dive into asymmetric client authentication — WorkOSworkos.com
- Understanding The Web Security Model, Part III: Basic Principles and the Origin Concepteducatedguesswork.org
- Themes from Real World Crypto 2022 - The Trail of Bits Blogblog.trailofbits.com
- WireGuard: Next Generation Kernel Network Tunnelwireguard.com
- RFC 9700: Best Current Practice for OAuth 2.0 Securitydatatracker.ietf.org
- Certificates | Computer Securitytextbook.cs161.org