Loading…
October 15-17 | Vancouver, British Columbia
View More Details  & Register Here
Techniques [clear filter]
Thursday, October 17
 

11:00am PDT

Hypermedia from the Trenches: Building a Decentralized Data-graph - Antonio Garotte, MuleSoft
Speakers
avatar for Antonio Garrote

Antonio Garrote

Principal Architect, MuleSoft
Principal architect at MuleSoft, I have been working in the API space for more than 15 years. My academic background is on linked data and semantics, but always with a focus on practical engineering problems that these areas of research could solve.



Thursday October 17, 2019 11:00am - 11:30am PDT
Junior Ballroom D
  Techniques, In Depth
  • Session Slides Included Yes

11:30am PDT

Are You Properly Using JWTs? - Philippe Leothaud, 42Crunch
JSON Web tokens (JWTs) are used massively in API-based applications as access tokens or to transport information across services. Unfortunately, JWT are often mis-used and incorrectly handled. Massive data breaches have occurred in the last 18 months due to token leakage and lack of proper of validation.

This session focuses on best practices and real world examples of JWT usage, where we cover:

- Typical scenarios where using JWT is a good idea
- Typical scenarios where using JWT is a bad idea!
- Principles of Zero trust architecture and why you should always validate
- Best practices to thoroughly validate JWTs and potential vulnerabilities if you don’t.
- Use cases when encryption may be required for JWT

Speakers
PL

Philippe Leothaud

Chief Architect, 42Crunch
Philippe Leothaud has over 20 years of experience in Identity Management, application security and integration. After 8 years at BeeWare (now acquired by DenyAll) as CTO of a company focusing on Web Application Firewall, Web SSO and Web Access Management, and 6 years at Vordel (now... Read More →



Thursday October 17, 2019 11:30am - 12:00pm PDT
Junior Ballroom D
  Techniques, In Depth
  • Experience Level Any
  • Session Slides Included Yes

12:00pm PDT

Security in OpenAPI Specification - Philippe Leothaud, 42Crunch
The enterprise use of APIs is growing exponentially. Companies face a difficult choice. They must shift towards a software-based, digital approach to service and product delivery – or get left behind. And to make matters more complicated, the adoption of microservices architectures has multiplied the number of API endpoints that you have to protect.

In this session, API security expert, Philippe Leothaud, will show how OpenAPI allows for making APIs secure by design and enabling DevSecOps for API infrastructures. He will also discuss which aspects of API security are covered today in OpenAPI contracts and what extensions to the specification are foreseen to have all aspects covered.

Speakers
PL

Philippe Leothaud

Chief Architect, 42Crunch
Philippe Leothaud has over 20 years of experience in Identity Management, application security and integration. After 8 years at BeeWare (now acquired by DenyAll) as CTO of a company focusing on Web Application Firewall, Web SSO and Web Access Management, and 6 years at Vordel (now... Read More →



Thursday October 17, 2019 12:00pm - 12:30pm PDT
Junior Ballroom D
  Techniques, In Depth
  • Experience Level Any
  • Session Slides Included Yes
 
Filter sessions
Apply filters to sessions.