Stupid Sexy Bearer Tokens: a deep dive into exploding OIDC sessions and hardening with DPoP
jiraky, reymerk, Giuseppe, toctou, Stefano Maistri
Standard OIDC bearer tokens are deceptively simple and highly attractive to developers, but they hide a structurally weak security posture: anyone who holds them can spend them. Following up on our previous deep dive @MOCA24 into securing OIDC code exchanges, this presentation is a hands-on, exploit-driven exploration of token-usage security.
We will begin by demonstrating how easily standard bearer tokens are stolen and replayed remotely from an attacker's terminal. We will then look "beyond the basics" to live-demo a hardened implementation of RFC 9449 (DPoP) using a Keycloak identity provider and an Express.js resource server.
Cybersecurity and Hacking
STAGE 1 (Section 9)