Загрузка...

PKCE Explained — Proof Key for Code Exchange | Identity Expert

This video describes security mechanisms as defined in published standards. It is not a substitute for a professional security review of your own implementation.

PKCE (Proof Key for Code Exchange, RFC 7636) stops code interception for browser and mobile apps that can't keep a client secret. Each login generates a random verifier, hashes it with SHA-256, and sends only the hash — a stolen code is useless without the verifier.

Covers: mechanics, HTTP payloads, three attacks, and OAuth 2.1's mandate.

• RFC 7636: https://datatracker.ietf.org/doc/html/rfc7636
• OAuth 2.1: https://datatracker.ietf.org/doc/draft-ietf-oauth-v2-1/

#pkce #oauth2 #appsecurity
---
Sources cited above are IETF RFCs, OIDF specifications, or W3C/OASIS standards — all freely reproducible for educational use.
For educational purposes only. Specs evolve — always check the latest version of the standard.

---

0:00 Introduction
0:20 Why public clients can't keep a secret
0:52 The analogy — a puzzle piece and a claim check
1:37 The problem — static secrets in mobile apps
2:19 How PKCE works — three moves
3:41 On the wire
4:39 Three attacks PKCE neutralises
5:38 OAuth 2.1 and beyond
6:25 Sources

#identityexpert #webdev

Видео PKCE Explained — Proof Key for Code Exchange | Identity Expert канала Identity Expert
Яндекс.Метрика
Все заметки Новая заметка Страницу в заметки
Страницу в закладки Мои закладки
На информационно-развлекательном портале SALDA.WS применяются cookie-файлы. Нажимая кнопку Принять, вы подтверждаете свое согласие на их использование.
О CookiesНапомнить позжеПринять