Visualizing the OAuth Flow and Why PKCE is Needed

Visualizing the OAuth Flow and Why PKCE is Needed

Ping Identity TV

4 года назад

20,955 Просмотров

Here's a short scenario to help visualize the attack that sparked the need for PKCE. Gain a deeper understanding of why PKCE is needed by watching this video. Give the free trial a go: http://ow.ly/vz8t50xMXAf

Тэги:

#oauth #oauth2.0 #oauth2 #pkce #identity #security #iam
Ссылки и html тэги не поддерживаются


Комментарии:

Vadim Emelin
Vadim Emelin - 09.09.2023 13:28

It describes why does PKCE exist but doesn't really describe how does it work :(

Ответить
Dinesh Srini
Dinesh Srini - 04.05.2023 05:12

But they did not explain how PKCE can secure this. (That was the reason I came to this video. The problem was pretty apparent.)

Ответить
Oskar Jaskólski
Oskar Jaskólski - 12.04.2023 12:02

X D

Ответить
Phyoe Wai Paing
Phyoe Wai Paing - 09.10.2022 09:45

Plz allow captains for this video if possible

Ответить
Abhay Soni
Abhay Soni - 04.09.2022 13:48

one minute does not the code flow requires client secret too. even though the other app got code how was it able to exchange the code without client secret

Ответить
S
S - 02.03.2022 07:08

There is no WHY here, sigh

Ответить
Vukkum Sai Prakash
Vukkum Sai Prakash - 20.10.2021 12:53

Fun explanation if need for PKCE (though not the PKCE flow itself explained)

Ответить
Victor O
Victor O - 28.08.2021 13:40

You didnt actually demonstrate PKCE hence you got a few thumbs down

Ответить
John Fernandes
John Fernandes - 24.01.2021 18:33

Just stick to a workflow!!! it is easier. Very complicate understanding

Ответить
Marc Allen
Marc Allen - 30.09.2020 18:44

Good job!!!!

Ответить
John Dee
John Dee - 30.07.2020 02:49

I still don't get it. PKCE seems to say "the OS is compromised, here is a half baked solution". My thoughts are, if the OS is compromised, there are NO SOLUTIONS -ZERO. I just don't get this. It seams like a scam to get me to use corporate products. Anyway, maybe I'm crazy, but I say this is non-sense. I still have no understanding how if the OS is even potentially compromised, how any data can be secure? Thanks for making the video though! Maybe I'm slightly less confused....

Ответить
Souvik Ghosh
Souvik Ghosh - 08.05.2020 14:31

Great Video! Can you please now create a video where you actually demo how PKCE can save me.

Ответить