Apidays New York 2023 - API Authentication Deep Dive: OAuth 2.0, Tokens, and JWTs

preview_player
Показать описание
Title: API authentication security unmasked: A thrilling dive into authentication exploits and unbreakable defenses
Speaker: Jeremiah Wilson, Security Analyst at Prescient Security

Dive into the complexities of API Authentication with Jeremiah Wilson, Security Analyst at Prescient Security. This video is a must-watch for tech enthusiasts and professionals navigating the digital landscape, offering a comprehensive exploration of OAuth 2.0, API tokens, and JSON Web Tokens (JWTs). Jeremiah breaks down critical security concepts, demonstrates how JWT misconfigurations can lead to security breaches and provides actionable insights on securing APIs against common vulnerabilities.

Explore the API ecosystem through Jeremiah's detailed analysis and live hacking demo, where he exposes the potential risks and teaches methods to fortify authentication processes. This session is not just theoretical but includes practical demonstrations that highlight the importance of robust security measures in API management.

Key takeaways include:
- Understanding OAuth 2.0 and its implementation
- Distinctions and uses of API tokens and JWTs
- Identification and mitigation of common API security vulnerabilities

Whether you're a developer, a security specialist, or just keen to learn more about API security, this video provides the knowledge you need to navigate the API ecosystem effectively.

#JwtValidation #ApiSecurityTips #JwtExploits #WebApplicationSecurity #SecureApiAuthentication

CHAPTERS:
0:15 - Introduction Agenda
1:14 - OWASP API Top 10 Overview
2:15 - API Authentication Basics
6:18 - Common Authentication Vulnerabilities
7:02 - JWT Token Components Explained
7:55 - JWT Misconfigurations Issues
9:33 - Live Demo: API Security
21:05 - Securing API Authentication
22:05 - Closing Remarks

**Join our community and explore more about APIs:**
Learn more on APIscene, the global media made by the community for the community:

Explore the API ecosystem with the API Landscape:

Deep dive into the API industry with our reports:

Subscribe to our global newsletter:
Рекомендации по теме