Deblokt DOO

Deblokt DOO Deblokt is providing IT services using Microsoft technology stack.

06/03/2020

Are they really unphishable?

Yes.

FIDO2 provides .

This is because FIDO2 authenticators check the origin before signing the assertion.

If the origin doesn't match the origin stored on the key the authentication ceremony will fail.

19/02/2020

Yes and no, depends on the scenario.

The application that persists the state while the application is running does not need cookies.

Examples for these would be native applications (mobile and desktop) or web applications like Single Page Application (SPA).

For stateless applications (MVC web apps for example) there must be a mechanism to persist the user session.

Auth cookie is usually used for that purpose.

If the auth cookie isn't issued the application would have to redirect to the Identity Provider and acquire token on each request which is inefficient and slow.

A cookie is also used on the Identity Provider side to persist the authenticated user session. This effectively enables the Single Sign-On (SSO) between applications.

12/02/2020

Access tokens (ie bearer token) and ID tokens contain user information like the subject (the unique identifier for a user) along with the claims for that user.

As long as the tokens are valid the claims within can't be updated.

Imagine a situation where a user is revoked or assigned administrator rights.

If the tokens have a 5-minute expiry the change will be reflected within the next 5 minutes as new tokens will have to be obtained from an Identity Provider.

To prevent a user from having to enter credentials every 5 minutes the long-lived refresh token should be used as it makes obtaining tokens transparent to the user.

Address

Miloša Obilića 25/4
Subotica
24000

Opening Hours

Monday 09:00 - 17:00
Tuesday 09:00 - 17:00
Wednesday 09:00 - 17:00
Thursday 09:00 - 17:00
Friday 09:00 - 17:00

Telephone

+381655250055

Alerts

Be the first to know and let us send you an email when Deblokt DOO posts news and promotions. Your email address will not be used for any other purpose, and you can unsubscribe at any time.

Contact The Business

Send a message to Deblokt DOO:

Share