
Are you sure your access tokens are really secure? - Wesley Cabus - NDC Copenhagen 2025
Keywords
Summary
149 words
Critical Evaluation
Value of the Information & Strength of the Argument
The talk provides valuable insights into real-world JWT security vulnerabilities, illustrated with concrete examples and demonstrations. The speaker’s argumentation is solid, based on his experience and the incidents he describes. He effectively explains complex attack vectors in an accessible manner, making the content valuable for developers and security professionals. The emphasis on testing and the introduction of an open-source template add practical value, enabling attendees to apply the lessons learned.
79 words
Title / Content Match
The title accurately reflects the content, which focuses on the security of access tokens and potential validation bypasses.
Quality & Reliability
8/10
The talk is based on real-world security incidents and demonstrates concrete attack vectors with practical testing approaches. The speaker is a customer success engineer at Duende Software, a company known for identity server solutions, lending credibility. However, the presentation is largely anecdotal and lacks formal citations or peer-reviewed sources.
Key Moments
Markers derived by PSI from the transcript: the creator did not define chapters.
- Introduction and story setup
- Explanation of JWT structure
- First attack: algorithm none bypass
- Second attack: self-signed tokens with JWK
- Discussion on validation libraries and trust
- Introduction of Jotguard template
- Demonstration of breaking tests with misconfiguration
- Algorithm confusion attack explanation
- Live demo of algorithm confusion
- Conclusion and recommendations
Cited Sources
- NDC Conferences — Conference website
- NDC Copenhagen — Conference website
Concurring Sources
Contribution & Novelties
The talk provides a practical, hands-on approach to testing JWT validation, addressing common but often overlooked vulnerabilities. The introduction of the open-source Jotguard template is a novel contribution, offering a reusable test suite for developers. The talk also highlights the importance of trust in open-source libraries and the need for continuous testing.
Pour aller plus loin :
- RFC 7515 - JSON Web Signature — Official specification for JWS, relevant to the signature validation discussed.
- RFC 7517 - JSON Web Key — Specification for JWK, central to the self-signed token attack.
- OWASP JWT Cheat Sheet — Practical guidance on JWT security, including algorithm confusion prevention.
104 words
Radar Profile
The radar profile shows high scores in information quantity and quality, with a moderate technical level and reliability. This indicates a well-balanced presentation that is informative and credible, though not extremely technical or heavily sourced.
💬 Sur les 0 commentaires analysés, aucune tendance n'est disponible.