About this talk
This talk by Bhaumik Shah explores the vulnerabilities in modern authentication systems, specifically focusing on OAuth, OpenID Connect (OIDC), and JSON Web Token (JWT) authentication flows. The speaker demonstrates real-world attacks, including token replay and session hijacking, while highlighting how insecure configurations can lead to system compromises. Practical defense strategies are also shared, providing insights into securing authentication processes against these modern threats.
More from this event
See all 91 talks →
BSidesSF 2026 - Opening Remarks (Sunday) (Reed Loden)
14:36
BSidesSF 2026 - Follow the data to learn the secret (Dylan Ayrey)
35:17
BSidesSF 2026 - Not My Vibe: When AI Coding Agents Go Off the Rails (Aonan Guan, Zhengyu Liu)
45:56
BSidesSF 2026 - "Ask the EFF" Panel (Panel)
45:30