What happens when you type google.com in a browser and press Enter? And what happens when you press the button "Sign in with Google" in the browser? Two of our speakers - Mauro Tempesta from the team bacaro_tour and Nikita Stupin from Mail.ru - know well the answer to the second question. Nikita will tell us about vulnerabilities OAuth 2.0 on moble devices and also he will show the most common and crucial vulnerabilities of usual OAuth 2.0, the mechanisms of defense and typical mistakes of developers. Mauro will present WPSE - a browser-side security monitor for web protocols which helps to prevent attacks on OAuth and SAML and to find vulnerabilities in different implementations of OAuth and its analogues.
In case you need it, the answer to the first question is here:
https://github.com/alex/what-happens-when
And you can register for the conference here:
https://ructf.org/registration/
Post #428
135

