Scott Brady (@scottbrady91) 's Twitter Profile
Scott Brady

@scottbrady91

I help developers learn OAuth and web security (he/him) hachyderm.io/@scottbrady

ID: 34642152

linkhttps://www.scottbrady.io calendar_today23-04-2009 15:33:47

1,1K Tweet

1,1K Followers

142 Following

UWEcyber (@uwecyber) 's Twitter Profile Photo

Delighted to welcome our #MSc #Cyber #Security #students to campus today - module intros, practical work and a fantastic UWEcyber guest talk from Scott Brady of #RockSolidKnowledge on password security!

Delighted to welcome our #MSc #Cyber #Security #students to campus today - module intros, practical work and a fantastic <a href="/UWEcyber/">UWEcyber</a> guest talk from <a href="/scottbrady91/">Scott Brady</a> of #RockSolidKnowledge on password security!
Jim Manico from Manicode Security (@manicode) 's Twitter Profile Photo

I’m having difficulty making a call for a cheatsheet regarding guidance to HMAC a password before sending it over TLS. Please chime in here if interested and have expertise in this area github.com/OWASP/CheatShe….

Scott Brady (@scottbrady91) 's Twitter Profile Photo

Understanding identity tokens: a deep dive into OpenID Connect's ID token. This is a reference piece, touching on who should use identity tokens, token format, validation, and when not to stuff them full of PII scottbrady91.com/openid-connect…

Frederik Raabye (@fraabye) 's Twitter Profile Photo

People still ask me questions about SSO for #Umbraco after my Umbraco Codegarden 2017 talk. My code hasn't been updated for ages and you should have a look at Scott Brady's articles on how to do it in Umbraco 9: scottbrady91.com/umbraco/backof… (back office) / scottbrady91.com/umbraco/fronte… (members)

Scott Brady (@scottbrady91) 's Twitter Profile Photo

Step-up authentication with OAuth and OpenID Connect: how to trigger step-up authentication using open standards scottbrady91.com/oauth/step-up-…

OpenID (@openid) 's Twitter Profile Photo

The OpenID Foundation is excited to announce the 2022 Kim Cameron Scholarship. Learn more about the opportunity to receive a scholarship to European Identity & Cloud Conference or Identiverse including the submission process and deadlines here: openid.net/2022/04/08/ann… #oidf

Pamela Dingle (@pamelarosiedee) 's Twitter Profile Photo

linktr.ee/oauth2 - a one-stop list of RFC numbers, nicknames and links to OAuth 2.0 specifications. Quick to scroll and an easy to remember resource for beginners! Good for presentations and for pretending your memory is perfect when making comments at OAuth Security Workshop #osw7

linktr.ee/oauth2 - a one-stop list of RFC numbers, nicknames and links to OAuth 2.0 specifications. Quick to scroll and an easy to remember resource for beginners!  Good for presentations and for pretending your memory is perfect when making comments at <a href="/secworkshop/">OAuth Security Workshop</a> #osw7
Kelly Shortridge (@swagitda_) 's Twitter Profile Photo

CamperBob2 on HN is the hero we deserve. Don’t mistake Rule of Cool for likelihood. (also, love to see the “Security Theater” barb enter common parlance... we used it in the Security Chaos Engineering book to label traditional infosec and it ruffled feathers (the truth hurts))

CamperBob2 on HN is the hero we deserve. Don’t mistake Rule of Cool for likelihood.

(also, love to see the “Security Theater” barb enter common parlance... we used it in the Security Chaos Engineering book to label traditional infosec and it ruffled feathers (the truth hurts))
Steve Syfuhs (@stevesyfuhs) 's Twitter Profile Photo

Periodic reminder that if your attack requires that you first somehow acquire the secret key to something, you have not in fact created a new attack.

Scott Brady (@scottbrady91) 's Twitter Profile Photo

Understanding JSON Web Encryption (JWE) - learn about the JWE format, why you need both JWE & JWS, and what encryption algorithms you'll be able to use. scottbrady91.com/jose/json-web-…

Felix Krause (@krausefx) 's Twitter Profile Photo

🔥 New Post: Announcing InAppBrowser - see what JavaScript commands get injected through an in-app browser 👀 TikTok, when opening any website in their app, injects tracking code that can monitor all keystrokes, including passwords, and all taps. krausefx.com/blog/announcin…

🔥 New Post: Announcing InAppBrowser - see what JavaScript commands get injected through an in-app browser

👀 TikTok, when opening any website in their app, injects tracking code that can monitor all keystrokes, including passwords, and all taps.

krausefx.com/blog/announcin…