- Популярные видео
- Авто
- Видео-блоги
- ДТП, аварии
- Для маленьких
- Еда, напитки
- Животные
- Закон и право
- Знаменитости
- Игры
- Искусство
- Комедии
- Красота, мода
- Кулинария, рецепты
- Люди
- Мото
- Музыка
- Мультфильмы
- Наука, технологии
- Новости
- Образование
- Политика
- Праздники
- Приколы
- Природа
- Происшествия
- Путешествия
- Развлечения
- Ржач
- Семья
- Сериалы
- Спорт
- Стиль жизни
- ТВ передачи
- Танцы
- Технологии
- Товары
- Ужасы
- Фильмы
- Шоу-бизнес
- Юмор
PKCE Explained — Proof Key for Code Exchange | Identity Expert
This video describes security mechanisms as defined in published standards. It is not a substitute for a professional security review of your own implementation.
PKCE (Proof Key for Code Exchange, RFC 7636) stops code interception for browser and mobile apps that can't keep a client secret. Each login generates a random verifier, hashes it with SHA-256, and sends only the hash — a stolen code is useless without the verifier.
Covers: mechanics, HTTP payloads, three attacks, and OAuth 2.1's mandate.
• RFC 7636: https://datatracker.ietf.org/doc/html/rfc7636
• OAuth 2.1: https://datatracker.ietf.org/doc/draft-ietf-oauth-v2-1/
#pkce #oauth2 #appsecurity
---
Sources cited above are IETF RFCs, OIDF specifications, or W3C/OASIS standards — all freely reproducible for educational use.
For educational purposes only. Specs evolve — always check the latest version of the standard.
---
0:00 Introduction
0:20 Why public clients can't keep a secret
0:52 The analogy — a puzzle piece and a claim check
1:37 The problem — static secrets in mobile apps
2:19 How PKCE works — three moves
3:41 On the wire
4:39 Three attacks PKCE neutralises
5:38 OAuth 2.1 and beyond
6:25 Sources
#identityexpert #webdev
Видео PKCE Explained — Proof Key for Code Exchange | Identity Expert канала Identity Expert
PKCE (Proof Key for Code Exchange, RFC 7636) stops code interception for browser and mobile apps that can't keep a client secret. Each login generates a random verifier, hashes it with SHA-256, and sends only the hash — a stolen code is useless without the verifier.
Covers: mechanics, HTTP payloads, three attacks, and OAuth 2.1's mandate.
• RFC 7636: https://datatracker.ietf.org/doc/html/rfc7636
• OAuth 2.1: https://datatracker.ietf.org/doc/draft-ietf-oauth-v2-1/
#pkce #oauth2 #appsecurity
---
Sources cited above are IETF RFCs, OIDF specifications, or W3C/OASIS standards — all freely reproducible for educational use.
For educational purposes only. Specs evolve — always check the latest version of the standard.
---
0:00 Introduction
0:20 Why public clients can't keep a secret
0:52 The analogy — a puzzle piece and a claim check
1:37 The problem — static secrets in mobile apps
2:19 How PKCE works — three moves
3:41 On the wire
4:39 Three attacks PKCE neutralises
5:38 OAuth 2.1 and beyond
6:25 Sources
#identityexpert #webdev
Видео PKCE Explained — Proof Key for Code Exchange | Identity Expert канала Identity Expert
Комментарии отсутствуют
Информация о видео
2 мая 2026 г. 5:18:15
00:05:37
Другие видео канала





















