nikhil.io

three things tagged “security”

What’s OAuth2 Anyway?

Excellent piece covering OAuth2 in way more depth than I needed for a class I’m taking. But as the author notes:

Thinking about why OAuth2 protocol has been designed the way it is, turned out to be a great exercise in threat modeling with immediate, straightforward and practical approaches to mitigate these threats. They can be reused to solve similar security concerns in other contexts outside of OAuth protocol, so you can benefit from a deep understanding of the protocol even if you are not a security expert who has to know the ins and outs of OAuth2.

There is no useless knowledge. Cached.

On Security Through Obscurity

Security by Obscurity is when you hide how a security measure works, not when you keep some part of it a secret. Daniel Miessler, “No, Moving Your SSH Port Isn’t Security by Obscurity” (Cached) As a former sysadmin (but no expert on security): This should be read and re-read. After which one…