217 - OAuth vs. SAML vs. OpenID Connect - Michael Schwartz
OAuth, SAML and OpenID Connect are the most important identity federation protocols in use today. Yet the many security architects struggle to express the differences between them. Front-channel, back-channel, assertion, JWT, claims, attributes, IDP, SP, OP, RP--there is a lot of jargon, and some of it seems to overlap. This compare / contrast session will help you understand the differences! Many application security experts are making important decisions about which identity federation protocol to use for single sign-on for their next-generation application platform. There has been a lot of innovation in the area of identity federation in the last few years, and it's hard to keep up. It's really helpful if security architects can be presented with a summary of what's the same (or just re-named), what's different, and what's new. No assumptions will be made about previous expertise. Each protocol will be given a summary introduction, with references to the parts of the standard that are most commonly used, and which parts are esoteric. The security level of an application is impacted based on the protocol and features used. SAML, OpenID Connect and OAuth offer several profiles, enabling the implementation of both high and low assurance trust frameworks. This topic will also be addressed to help clarify which solutions are best suited for which requirements.

OAuth 2.0 and OpenID Connect (in plain English)

Introduction to SAML - Chalktalk on what is it, how it is used

Introduction to OAuth 2.0 and OpenID Connect By Philippe De Ryck

An Illustrated Guide to OAuth and OpenID Connect

How SAML, OAUTH, and other Identity Federation Solutions Work in a Windows Enterprise

A Developer's Guide to SAML

Introduction to OAuth 2.0 and OpenID Connect • Philippe De Ryck • GOTO 2018

7 Authentication Concepts Every Developer Should Know

Explain it to Me Like I’m 5: Oauth2 and OpenID

Everything You Ever Wanted to Know About OAuth and OIDC

2017 - Improving dynamic vulnerability scanners with static code analysis - Caleb Coffie

oAuth and OpenID connect | Most confusing topic in plain english

Understanding Authentication and Authorisation Protocols

OAuth and OpenID Connect Deep Dive | Travis Spencer | API Conference 2018

Standards 201 - SAML & OIDC - Intro to Identity Series

Authentication as a Microservice

SAML vs OAuth vs OIDC (explained simply!)
![How Netflix Is Solving Authorization Across Their Cloud [I] - Manish Mehta & Torin Sandall, Netflix](https://i.ytimg.com/vi/R6tUNpRpdnY/hqdefault.jpg?sqp=-oaymwEjCNACELwBSFryq4qpAxUIARUAAAAAGAElAADIQj0AgKJDeAE=&rs=AOn4CLCFramTuBW6fda4cLg9Yz802mjCMA)
How Netflix Is Solving Authorization Across Their Cloud [I] - Manish Mehta & Torin Sandall, Netflix

Demystifying SAML Using Spring Security

