Subscribe!

Identity and Access Control

Download this episode

Download Video

Description

Today I woke up thinking that talking about Identity and Access Control and how your strategy around that affects you (web-) app's architecture without going too deeply into the security lingo that usually comes with it. Here's the 40 minute result.

I start with HTTP's "native" authentication model RFC 2617 and how that's universally bad, with both Basic and Digest authentication having issues Digest being, ironically worse for the overall security strategy. Then I dive into why models that use tokens (or cookies) are better in terms of security and scalability and explore a range of variations amongst those.

Embed

Format

Available formats for this video:

Actual format may change based on video formats available and browser capability.

    The Discussion

    • codingoutlo​ud

      Clemens mentions a Firefox plug-in that helps steal session cookies over wifi, but he could not recall the name. I believe he was thinking of Firesheep: http://codebutler.com/firesheep/

    • kentweare

      A great primer for those new to ACS and federated security.  Thanks for publishing this.

       

      Kent

    • ilija injac

      This is really a great introduction into ACS and its feature-set on a conceptual base. What I miss the most, are some samples, or better some video demonstration, about WCF and best practices regarding service throttling on Azure. A video only about WCF being hosted in Worker Roles on Azure using ACS would also be great Smiley

      Thank you.

       

      Ilija

       

    Comments closed

    Comments have been closed since this content was published more than 30 days ago, but if you'd like to continue the conversation, please create a new thread in our Forums, or Contact Us and let us know.