Stefano Maistri
I currently work as Principal Security Consultant at IMQ Group - Intuity S.p.A., where I conduct penetration testing, secure code reviews, threat modeling, and DevSecOps assessments. Alongside consulting, I'm involved in academia as external professor for the Cyber Security Master's program at the University of Bologna.
Session
Standard OIDC bearer tokens are deceptively simple and highly attractive to developers, but they hide a structurally weak security posture: anyone who holds them can spend them. Following up on our previous deep dive @MOCA24 into securing OIDC code exchanges, this presentation is a hands-on, exploit-driven exploration of token-usage security.
We will begin by demonstrating how easily standard bearer tokens are stolen and replayed remotely from an attacker's terminal. We will then look "beyond the basics" to live-demo a hardened implementation of RFC 9449 (DPoP) using a Keycloak identity provider and an Express.js resource server.