Skip to content

Authentication & Identity

Authentication answers "who are you?" Identity protocols answer "how do I prove it to a third party?" The attacks in this section exploit weaknesses in how that proof is established, transmitted, stored, or verified.

Topics in this section

Doc Focus
Authentication & Session Credential stuffing, spraying, MFA bypass, reset poisoning, fixation
JWT Token Security Algorithm confusion (RS256→HS256), none alg, key confusion
OAuth 2.0 & OIDC State parameter CSRF, redirect_uri abuse, implicit flow leakage
OIDC Deep Dive ID token validation, nonce binding, hybrid flow
SAML XML signature wrapping, XXE via assertion, replay
SSO Cross-domain trust abuse, federation misconfig
WebAuthn & Passkeys Ceremony flow, origin binding, attestation
MFA & Step-Up Auth OTP bypass, SIM swap, push fatigue
Password Authentication KDF selection, timing attacks, reset flows
Session Management Fixation, hijacking, cookie attributes
Token Exchange RFC 8693, scope reduction, impersonation
mTLS Certificate binding, header spoofing in proxied flows
SPIFFE & SPIRE Workload identity, SVID issuance, attestation
OpenID Federation Trust chain, metadata endpoints, key rollover

The core invariant

Proof of identity must be bound to a specific session, audience, and time window. Any token or credential that travels without audience binding, expiry, or channel binding can be replayed by a different principal against a different resource.