[germany-chapter] 03.06.2025 18:00 OWASP Stammtisch Stuttgart: Modern Authentication Demystified

7 views
Skip to first unread message

Sven Strittmatter

unread,
May 21, 2025, 10:33:02 AMMay 21
to germany...@owasp.org
Hello 👋

Nothing planned for 03.06.2025 evening? It's OWASP Stammtich Stuttgart
again from 18:00 in the
premises of iteratec GmbH (Zettachring 6, 70567 Stuttgart).

Topic: Modern Authentication Demystified - A deep dive into Spring
Security's latest innovations

In this session, we explore the latest advancements in Spring Security
that are
reshaping how we secure modern applications. With a focus on practical
applications, we’ll discuss the revolutionary Passkey Authentication, a
password-less and phishing-resistant mechanism based on WebAuthn and FIDO2
standards. Next, we’ll examine One-Time Tokens, a robust way to secure
sensitive
actions and enhance user experience for scenarios like password resets and
transaction approvals. Finally, we’ll delve into the emerging concept of
Token
Exchange, which facilitates seamless cross-service authentication by
securely
exchanging OAuth tokens. Attendees will gain a clear understanding of
how these
new features work, their real-world use cases, and best practices for
integrating them into their Spring Security applications.

Bio: Andreas Falk has worked on enterprise application development
projects for
over twenty-five years. Currently, he is a senior managing consultant for
Novatec Consulting (recently merged with CGI), located in Germany. In
various
projects, he has since been around as an architect, coach, and
developer. His
focus is on the agile development of cloud-native enterprise Java
applications
using the complete Spring platform. As a member of the Open Web Application
Security Project (OWASP), he likes to have a closer look at all aspects of
application security as well. Andreas is also a frequent speaker at
conferences
like Spring I/O, OWASP, and Devoxx.

Speaker: Andreas Falk

Andreas Falk has worked on enterprise application development projects
for over
twenty-five years. Currently, he is a senior managing consultant for Novatec
Consulting (recently merged with CGI), located in Germany. In various
projects,
he has since been around as an architect, coach, and developer. His
focus is on
the agile development of cloud-native enterprise Java applications using the
complete Spring platform. As a member of the Open Web Application Security
Project (OWASP), he likes to have a closer look at all aspects of
application
security as well. Andreas is also a frequent speaker at conferences like
Spring
I/O, OWASP, and Devoxx.

Details:
https://www.meetup.com/de-DE/owasp-stuttgart-chapter/events/305584778/

CU
--sven

Reply all
Reply to author
Forward
0 new messages