RomHack Camp 2026

Stupid Sexy Bearer Tokens: a deep dive into exploding OIDC sessions and hardening with DPoP
2026-10-02 , STAGE 1 (Section 9)
Language: Italiano

Standard OIDC bearer tokens are deceptively simple and highly attractive to developers, but they hide a structurally weak security posture: anyone who holds them can spend them. Following up on our previous deep dive @MOCA24 into securing OIDC code exchanges, this presentation is a hands-on, exploit-driven exploration of token-usage security.
We will begin by demonstrating how easily standard bearer tokens are stolen and replayed remotely from an attacker's terminal. We will then look "beyond the basics" to live-demo a hardened implementation of RFC 9449 (DPoP) using a Keycloak identity provider and an Express.js resource server.

Dr. Zago holds a PhD from the University of Murcia, Spain. He is currently based in Verona, Italy, working as a cybersecurity engineer (official registration code VR-A-4783). Since 2024 he works for the Oniverse Group as Cyber Security engineer.

His research has focused on Artificial Intelligence for cybersecurity, including machine learning solutions for network intrusion detection systems, big data and sentiment analysis to identify social bots on social media platforms; and, anomaly detection in users' behavioural patterns for authentication and authorization purposes.

toctou ha conseguito una laurea magistrale in Ingegneria della Sicurezza informatica presso l'Università di Verona. Ha iniziato la sua carriera come analista di Cyber Security, cambiando poi bruscamente rotta diventando Senior Oracle Database Administrator con oltre dieci anni di esperienza nel settore IT. Da poco è poi riuscito a tornare alle radici virando di nuovo carriera e diventando Penetration Tester. È certificato come OffSec Certified Professional (OSCP) e OffSec Experienced Penetration Tester (OSEP). Come appassionato di cybersecurity è sempre desideroso di studiare e ampliare le conoscenze e le competenze pratiche in materia di sicurezza informatica nel tempo libero e, come attività secondaria, attualmente crea macchine vulnerabili per OffSec come autore freelance.

I currently work as Principal Security Consultant at IMQ Group - Intuity S.p.A., where I conduct penetration testing, secure code reviews, threat modeling, and DevSecOps assessments. Alongside consulting, I'm involved in academia as external professor for the Cyber Security Master's program at the University of Bologna.