Identity Server Update with Dominick Baier and Brock Allen
What's the latest for Identity Server? While at NDC in Porto, Carl and Richard chatted with Dominick Baier and Brock Allen about their latest work on Identity Server. The conversation goes through the various current generations of attacks on web pages, how Single Page Apps behave differently, and more! Great conversation about the current state of web-based security and how you can do more.
Guests:
Dominick Baier
Dominick Baier spent most of his professional career implementing security systems for his customers and reading protocol specifications. This resulted in a number of popular open-source projects like IdentityServer and IdentityModel. Since 2020 he runs Duende Software Inc together with his longtime friend and colleague Brock Allen. Duende provides a sustainable home for the IdentityServer project and is the one-stop-shop for all things OpenID Connect and OAuth for .NET-based companies.
Brock Allen
Brock Allen has worked for many years as an application security architect and has specialized in .NET, web development, and web-based security for over 20 years. During that time, he co-authored several open-source security frameworks including IdentityServer, IdentityModel, and oidc-client-js. He also is an MVP, and a contributor to the ASP.NET platform. Most recently he co-founded Duende Software with his colleague of many years Dominick Baier.
Links:
- Dad Jokes https://github.com/wesbos/dad-jokes
- IdentityServer https://identityserver.io/
- CORS https://enable-cors.org/
- Cross-Site Request Forgery https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF)
- Cross-Site Scripting https://www.owasp.org/index.php/Cross-site_Scripting_(XSS)
- OWASP Top 10 https://www.owasp.org/images/7/72/OWASP_Top_10-2017_(en).pdf.pdf
- Content Security Policy https://content-security-policy.com/
- Angular https://angular.io/
- React https://reactjs.org/
- Make CSP Great Again https://www.youtube.com/watch?v=uf12a-0AluI
- Proof Key for Code Exchange https://oauth.net/2/pkce/
- Develop More Secure ASP.NET Apps https://dl.acm.org/citation.cfm?id=1203288