Beyond Passwords: How WebAuthn Actually Works • Eli Holderness • GOTO 2023
This presentation was recorded at GOTO Amsterdam 2023. #GOTOcon #GOTOams https://gotoams.nl Eli Holderness - Developer Advocate at Scaleway @Eli Holderness RESOURCES https://bsky.app/profile/eli.holderne... / eliholderness / eli-holderness-4890b886 https://hachyderm.io/@eli ABSTRACT Passwords are a pain, and we all know it. They're either insecure or impossible to remember, and password managers can only go so far. How can we do better? The answer is WebAuthn. WebAuthn is set of standards that allows you to use hardware authentication tokens (like a YubiKey) to authenticate with web services, and it's absolutely magic. Join me for a deep dive on what WebAuthn actually is, how it works, and how to implement it in your own web services. We'll also discuss the practicalities of using hardware tokens in practice, the protocols they use to interface with your devices, and the mysterious cryptography that they use to keep you safe. [...] Read the full abstract here: https://gotoams.nl/2023/sessions/2450 RECOMMENDED BOOKS Liz Rice • Container Security • https://amzn.to/3oU4iJe Liz Rice • Kubernetes Security • https://www.oreilly.com/library/view/... Aaron Parecki • OAuth 2.0 Simplified • https://amzn.to/2A3IMOf Aaron Parecki • OAuth 2.0 Servers • https://amzn.to/3ecHEsz Aaron Parecki • The Little Book of OAuth 2.0 RFCs • https://amzn.to/3i7qnlC Erdal Ozkaya • Cybersecurity: The Beginner's Guide • https://amzn.to/2T6OIj3 Richer & Sanso • OAuth 2 in Action • https://amzn.to/3hXiAH6 / gotocon / goto- / gotoconferences #Privacy #PasswordSecurity #WebAuthn #Passwords #Security #CyberSecurity #YubiKey #EliHolderness #SoftwareEngineering #Programming Looking for a unique learning experience? Attend the next GOTO conference near you! Get your ticket at https://gotopia.tech Sign up for updates and specials at https://gotopia.tech/newsletter SUBSCRIBE TO OUR CHANNEL - new videos posted almost daily. https://www.youtube.com/user/GotoConf...

Going Passwordless - A Practical Guide to Passkeys in ASP.NET Core

OAuth 2.0 and OpenID Connect (in plain English)

Passkeys Explained: FIDO’s Passwordless Authentication Deep Dive

PASSKEYS - What they are, why we want them and how to use them!

Capture the 'Why': Building Context Graphs for Explainable AI Agents on AWS

Creating Local-First Collaboration Software with Automerge • Martin Kleppmann • GOTO 2023

How FIDO2 and WebAuthn Stop Account Takeovers

How Work Works • James Lewis • GOTO 2023

Passkeys Explained: Are They Actually Better Than Passwords?

WebAuthn: Strong Authentication vs Privacy vs Convenience - Suby Raman

Cybersecurity Architecture: Networks

Getting Started with WebAuthn with Nick Steele

How Passkeys Work - Computerphile

An Illustrated Guide to OAuth and OpenID Connect

The insecurity of OAuth 2.0 in frontends - Philippe de Ryck - NDC Security 2023

The One Where We Threat Model During Development • Izar Tarandach • GOTO 2023

10 Learnings From Running Production Infrastructure at Google • Christof Leng • GOTO 2023

ASP.NET Community Standup - Passwordless authentication with Passkeys in .NET 10

"Webauthn, Passkeys, and You - The Future of Authentication" - William Brown (Everything Open 2023)

