BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//cfp.romhack.io//romhack-camp-2026//speaker//WWMB3L
BEGIN:VTIMEZONE
TZID:CET
BEGIN:STANDARD
DTSTART:20001029T040000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=10
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20000326T030000
RRULE:FREQ=YEARLY;BYDAY=-1SU;BYMONTH=3
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
UID:pretalx-romhack-camp-2026-RLARMV@cfp.romhack.io
DTSTART;TZID=CET:20261002T110000
DTEND;TZID=CET:20261002T114000
DESCRIPTION:Standard OIDC bearer tokens are deceptively simple and highly a
 ttractive to developers\, but they hide a structurally weak security postu
 re: anyone who holds them can spend them. Following up on [our previous de
 ep dive](https://www.youtube.com/watch?v=ehSkbR-YuZw) @MOCA24 into securin
 g OIDC code exchanges\, this presentation is a hands-on\, exploit-driven e
 xploration of token-usage security.\nWe will begin by demonstrating how ea
 sily standard bearer tokens are stolen and replayed remotely from an attac
 ker's terminal. We will then look "beyond the basics" to live-demo a harde
 ned implementation of [RFC 9449](https://datatracker.ietf.org/doc/html/rfc
 9449) (DPoP) using a Keycloak identity provider and an Express.js resource
  server.
DTSTAMP:20260921T190754Z
LOCATION:STAGE 1 (Section 9)
SUMMARY:Stupid Sexy Bearer Tokens: a deep dive into exploding OIDC sessions
  and hardening with DPoP - jiraky\, reymerk\, Giuseppe\, toctou\, Stefano 
 Maistri
URL:https://cfp.romhack.io/romhack-camp-2026/talk/RLARMV/
END:VEVENT
END:VCALENDAR
