<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>conferences Archives - IDPro</title>
	<atom:link href="https://idpro.org/tag/conferences/feed/" rel="self" type="application/rss+xml" />
	<link>https://idpro.org/tag/conferences/</link>
	<description>The Professional Organization for Digital Identity Management</description>
	<lastBuildDate>Mon, 31 Aug 2026 21:25:12 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://idpro.org/wp-content/uploads/2023/07/cropped-idpro_stickerA-circle-100-32x32.jpg</url>
	<title>conferences Archives - IDPro</title>
	<link>https://idpro.org/tag/conferences/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Symbiosis: Identiverse and IDPro</title>
		<link>https://idpro.org/symbiosis-identiverse-and-idpro/</link>
		
		<dc:creator><![CDATA[Elizabeth Garber]]></dc:creator>
		<pubDate>Mon, 31 Aug 2026 13:26:30 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[conferences]]></category>
		<category><![CDATA[iam]]></category>
		<category><![CDATA[identiverse]]></category>
		<guid isPermaLink="false">https://idpro.org/?p=3079</guid>

					<description><![CDATA[<p>Andrew Hindle reflects on the history between IDPro and Identiverse - and encourages IDPros to prepare for the annual Call for Presentations, which opens in October.</p>
<p>The post <a href="https://idpro.org/symbiosis-identiverse-and-idpro/">Symbiosis: Identiverse and IDPro</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong> by Andrew Hindle</strong><br></p>



<p class="wp-block-paragraph">IDPro and Identiverse have always had a close relationship. IDPro was formally launched at Cloud Identity Summit 2017 in Chicago (the same year we announced the rebrand to Identiverse) with a main stage talk by Ian Glazer and Sarah Cecchetti; for several years after, the two organisations maintained a semi-formal agreement, identifying Identiverse as the &#8216;home event&#8217; of IDPro. Eventually, that agreement was allowed to lapse—it really wasn&#8217;t needed anymore, given the depth of engagement IDPro members have with the event.</p>



<p class="wp-block-paragraph">The relationship shows up in a number of ways—informal gatherings, formal IDPro events, discount codes, constructive feedback from the community to the organisers, and much more besides&#8230;. But nowhere is it as apparent as in the responses we get from IDPro members to the annual Call for Presentations (&#8220;CFP&#8221;).</p>



<p class="wp-block-paragraph">The core of the Identiverse agenda revolves around sharing leading practices: &#8220;here&#8217;s a problem I ran into, here&#8217;s how I solved it&#8221; (or sometimes &#8220;here are solutions I&#8217;m considering&#8221;). Who better than IDPro members to provide those kinds of perspectives?&nbsp; Every year, the CFP is advertised via IDPro Connect Slack. Every year, I see ever more draft proposals being shared, ideas being floated, and advice being sought.</p>



<p class="wp-block-paragraph">In case you didn&#8217;t know, nigh on 80% of the main Identiverse agenda comes through the CFP. We&#8217;ve had nearly two decades to refine the review and selection process; and whilst it will never be perfect—and is consequently the subject of routine, incremental review and improvement, even today—we have over that time established, tested, refined, and in some cases entirely replaced, a range of mechanisms that help us to ensure a fair process which ultimately results in a comprehensive and balanced agenda.&nbsp; (If you&#8217;d like to know more, I&#8217;ve previously written in more detail about the agenda-building process in &#8220;The Art and Science of Agenda Building&#8221;, at https://www.hindleconsulting.com/posts/agenda_building/)</p>



<p class="wp-block-paragraph">Identiverse—like IDPro—is also growing rapidly, in lockstep with a profession and an industry that are increasingly understood together as a (the!) vital enabler of the digital landscape. Partly as a result, we receive many more proposals every year than we can possibly accommodate on the agenda—for the 2026 CFP, by a factor of 5 —and we expect this will only increase in the coming years.</p>



<p class="wp-block-paragraph">It&#8217;s at this point that people often ask me, &#8220;Well, if my chances are so slim, why should I propose?&#8221;&nbsp; And to that question, I have several answers!&nbsp; First: the act of preparing and submitting a proposal is, in and of itself, useful work. It can help refine and focus ideas; it can lead to new revelations or approaches to consider and discuss with others; and it&#8217;s a good way to sharpen the skills of distilling and clearly communicating complex concepts. On that latter point: yes, AI tools can help (although don&#8217;t feel that you have to, or even that you should use LLMs for this kind of work: they are just tools!): but only if given clear prompts to start with, and with careful editing and iteration during the process&#8230; and those are great skills to hone, too.</p>



<p class="wp-block-paragraph">Even if your proposal isn&#8217;t accepted, it <strong>will</strong> be read and reviewed, which in turn helps inform the committee as to what matters topically to the community. That contribution, invisible to you though it may be, is nonetheless hugely influential in the development of the conference agenda, year after year.</p>



<p class="wp-block-paragraph">You may, of course, choose to submit your proposal to several events, getting more than one-time use from your work. (Authenticate is another identity-focused conference that operates a very similar process to Identiverse, and is worth your consideration. There are others, too!)&nbsp; Exercise some caution when you do this: several conferences ask whether your talk has been submitted to, or delivered at, other events. Don&#8217;t make assumptions about why that question is being asked: sometimes (as for Identiverse) it&#8217;s simply another data point for the committee. Do answer honestly—any conference that operates a rigorous process like Identiverse will easily find out if you mislead, and that can absolutely affect selection chances in future years!</p>



<p class="wp-block-paragraph">But perhaps the most compelling reason is this: submitting a proposal to speak provides no guarantee whatsoever that your talk will be selected. But it&#8217;s a cast-iron certainty that your proposal cannot be selected if you don&#8217;t submit it!</p>



<p class="wp-block-paragraph">The Identiverse 2027 Call for Presentations will open in October. Keep your eyes open for when it does. Talk to your colleagues, your friends, your peers. Get advice from the IDPro community about how to refine your proposal. And then get your work in front of the committee. It&#8217;s one of the best ways to contribute to the profession that I can think of.</p>



<h2 class="wp-block-heading"><br><br>About the Author</h2>



<div class="wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex">
<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow" style="flex-basis:100%">
<figure class="wp-block-image size-full is-resized"><img fetchpriority="high" decoding="async" width="594" height="544" src="https://idpro.org/wp-content/uploads/2023/08/andrewHindle-e1692807177455.jpg" alt="" class="wp-image-2342" style="width:361px;height:auto" srcset="https://idpro.org/wp-content/uploads/2023/08/andrewHindle-e1692807177455.jpg 594w, https://idpro.org/wp-content/uploads/2023/08/andrewHindle-e1692807177455-300x275.jpg 300w" sizes="(max-width: 594px) 100vw, 594px" /></figure>
</div>
</div>



<p class="wp-block-paragraph">Andrew Hindle is an independent consultant and board advisor with deep expertise in digital identity, privacy, cybersecurity, and corporate governance, built across 25+ years in the global software industry. He works with boards, executives, and founders to navigate growth, risk, and strategic change in complex, fast-paced environments.</p>



<p class="wp-block-paragraph"><br>Andrew currently serves as a Non-Executive Director at Curity; as a board member at Women in Identity; and as Chair of the UK Advisory Board at the Kantara Initiative. He is a co-founder of The Identity Salon, and Conference Chair for Identiverse and Authenticate, where he works closely with industry leaders to curate high-quality, practitioner-focused content for the digital identity community. Andrew is also a Board Emeritus at IDPro, of which he was a founding member.</p>



<div class="wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex">
<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow" style="flex-basis:25%">
<figure class="wp-block-gallery has-nested-images columns-2 is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img decoding="async" width="600" height="600" data-id="1985" src="https://idpro.org/wp-content/uploads/2022/10/IDPro-Emeritus-Badge.png" alt="" class="wp-image-1985" srcset="https://idpro.org/wp-content/uploads/2022/10/IDPro-Emeritus-Badge.png 600w, https://idpro.org/wp-content/uploads/2022/10/IDPro-Emeritus-Badge-300x300.png 300w, https://idpro.org/wp-content/uploads/2022/10/IDPro-Emeritus-Badge-150x150.png 150w, https://idpro.org/wp-content/uploads/2022/10/IDPro-Emeritus-Badge-320x320.png 320w" sizes="(max-width: 600px) 100vw, 600px" /></figure>
</figure>
</div>



<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow" style="flex-basis:25%">
<figure class="wp-block-image size-large"><img decoding="async" width="600" height="600" src="https://idpro.org/wp-content/uploads/2023/06/IDPro_BoK_Badges_R5__Founding_Member.png" alt="" class="wp-image-2272" srcset="https://idpro.org/wp-content/uploads/2023/06/IDPro_BoK_Badges_R5__Founding_Member.png 600w, https://idpro.org/wp-content/uploads/2023/06/IDPro_BoK_Badges_R5__Founding_Member-300x300.png 300w, https://idpro.org/wp-content/uploads/2023/06/IDPro_BoK_Badges_R5__Founding_Member-150x150.png 150w, https://idpro.org/wp-content/uploads/2023/06/IDPro_BoK_Badges_R5__Founding_Member-320x320.png 320w" sizes="(max-width: 600px) 100vw, 600px" /></figure>
</div>



<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow" style="flex-basis:25%">
<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="600" height="600" src="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author.png" alt="" class="wp-image-2390" srcset="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author.png 600w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-300x300.png 300w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-150x150.png 150w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-320x320.png 320w" sizes="auto, (max-width: 600px) 100vw, 600px" /></figure>
</div>



<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow" style="flex-basis:25%">
<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="346" height="350" src="https://idpro.org/wp-content/uploads/2025/11/image-2.png" alt="" class="wp-image-2898" srcset="https://idpro.org/wp-content/uploads/2025/11/image-2.png 346w, https://idpro.org/wp-content/uploads/2025/11/image-2-297x300.png 297w" sizes="auto, (max-width: 346px) 100vw, 346px" /></figure>
</div>
</div>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://idpro.org/symbiosis-identiverse-and-idpro/">Symbiosis: Identiverse and IDPro</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The OAuth Security Workshop 2025</title>
		<link>https://idpro.org/the-oauth-security-workshop-2025/</link>
		
		<dc:creator><![CDATA[VTM Web Services]]></dc:creator>
		<pubDate>Thu, 27 Mar 2025 19:12:17 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Newsletter]]></category>
		<category><![CDATA[conferences]]></category>
		<category><![CDATA[OSW]]></category>
		<guid isPermaLink="false">https://idpro.org/?p=2761</guid>

					<description><![CDATA[<p>The OAuth Security Workshop 25 (OSW) took place in Reykjavik, Iceland this year, in the last week of February. Currently [&#8230;]</p>
<p>The post <a href="https://idpro.org/the-oauth-security-workshop-2025/">The OAuth Security Workshop 2025</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">The<a href="https://oauth.secworkshop.events/"> OAuth Security Workshop</a> 25 (OSW) took place in<a href="https://oauth.secworkshop.events/osw2025"> Reykjavik, Iceland</a> this year, in the last week of February. Currently in its 10th year, the workshop was initially created by two different research groups from the Universities of Ruhr-Bochum and Trier who independently discovered attacks on OAuth and OpenID Connect around the same time. These researchers first met in Darmstadt in 2015 with members of the OAuth working group to discuss the issues they surfaced and find mitigation strategies. The participants also decided that given the need for a better exchange of information and knowledge, a regular meeting or event was necessary. The OAuth Security Workshop was born, with the goal of ensuring that research and standardization efforts go in sync. Since then, the OSW has been run and organized independently by<a href="https://www.linkedin.com/in/dr-fett/"> Dr Daniel Fett</a>,<a href="https://www.linkedin.com/in/gschmitz/"> Guido Schmitz</a>,<a href="https://www.linkedin.com/in/steinar-noem-3845a82/"> Steinar Noem</a> without corporate backing or funding. Thankfully, individual workshops have corporate sponsors, but we still have to thank Daniel, Guido, and Steinar for their volunteer efforts in keeping this community alive and thriving for the past decade! As participants like to point out themselves, OSW is a meeting place for a couple hundred geeks, but those are the geeks who actually drive those standards for Identity that the current World Wide Web is built upon!</p>



<h2 class="wp-block-heading">OSW Sessions of Interest</h2>



<p class="wp-block-paragraph">OSW is itself part conference, part unconference. The mornings are dedicated to proper talks, keynotes, and sessions for different horizons – students, researchers, security architects, seasoned RFC writers, thought leaders, startup founders, and even<a href="https://digitalidadvancement.org/"> Digital Identity Advancement Foundation</a> “<a href="https://digitalidadvancement.org/awards-and-grants/vittorio/">Vittorio Bertocci Award</a>” grantees. The afternoons are open for unconference-style open sessions, the contents of which are decided each day by popular vote. Several tracks were thus discussed, these being the latest and greatest work currently in progress or published in the OAuth universe at large.&nbsp;</p>



<h3 class="wp-block-heading">Verifiable Credentials</h3>



<p class="wp-block-paragraph">A set of sessions was dedicated to the various groups working on Verifiable Credentials and related specs (<a href="https://openid.net/sg/openid4vc/">OID4VC</a>, etc.).<a href="https://www.linkedin.com/in/kristinayasuda/"> Kristina Yasuda</a> and her peers showed that a lot of effort has been going into standardizing the formats for representing credentials, for building trust frameworks, and ensuring that these digital credentials can be read, presented and understood, and most importantly, trusted. A huge driver here is still the pan-European<a href="https://digital-strategy.ec.europa.eu/en/policies/eidas-regulation"> eIDAS</a> initiative, whose goal is to provide all European citizens with Digital Credentials.</p>



<h3 class="wp-block-heading">WIMSE-cal Workloads</h3>



<p class="wp-block-paragraph">On another tack, a lot of work has been going into securing Workloads, with the advent of the new Transaction Tokens and<a href="https://datatracker.ietf.org/doc/draft-ietf-wimse-arch/"> WIMSE</a> specifications, as well as the new implementations of the not-so-new<a href="https://spiffe.io/"> SPIFFE</a> framework. As defined in the<a href="https://datatracker.ietf.org/doc/draft-ietf-oauth-transaction-tokens/"> Transactions Token spec</a>, a Workload is “An independent computational unit that can autonomously receive and process invocations, and can generate invocations of other workloads. Examples of workloads include containerized microservices, monolithic services and infrastructure services such as managed databases”. This also applies to our friends the AI Agents.<a href="https://www.linkedin.com/in/pieter-kasselman-0259862/"> Pieter Kasselman</a> highlighted that workloads have two main problems: providing them with a provable unique identity that can enable them to authenticate with each other (support of which can be provided through SPIFFE, but also through a new concept of a Workload Identity Token or<a href="https://datatracker.ietf.org/doc/draft-ietf-wimse-s2s-protocol/03/"> WIT</a>), and ensuring that the same context is shared across all the workloads participating in the same transaction (achieved through Transaction Tokens). Access to any resource by any of these Workloads can then be properly authorized within the context of the operation at hand.</p>



<h3 class="wp-block-heading">The Next Member of the OAuth Family</h3>



<p class="wp-block-paragraph">This topic led to some good follow-up discussions after<a href="https://www.linkedin.com/in/justinricher/"> Justin Richer</a> presented the RFC on<a href="https://datatracker.ietf.org/doc/rfc9421/"> HTTP message signature</a>, an alternative to<a href="https://datatracker.ietf.org/doc/html/rfc9449"> DPoP</a>, one of the legitimate children of OSW. What would happen if the workload couldn’t access the Authorization Server or the client key material? By the end of the conference<a href="https://datatracker.ietf.org/doc/html/draft-richer-oauth-tmb-claim"> a new proposal was submitted</a> to IETF. Discussions in<a href="https://www.ietf.org/meeting/122/"> Bangkok</a> promise to be epic.</p>



<h3 class="wp-block-heading">FAPI</h3>



<p class="wp-block-paragraph">On the development/engineering security side, the<a href="https://openid.net/specs/fapi-security-profile-2_0-final.html"> FAPI 2.0</a> specification was also released recently. It included various updates to the security posture required from its various participants. As for gauging the security of Web Applications, the Open Worldwide Application Security Project (OWASP) just released its version 5.0 of its Application Security Verification Standard (<a href="https://github.com/OWASP/ASVS">ASVS</a>).<a href="https://www.linkedin.com/in/elarlang/"> Elar Lang</a> presented the ASVS project, whose primary goal is to provide an open application security standard for web apps and web services of all types. The standard provides a set of controls that can be used to assess or test the security of any system. Implementers can thus choose which controls to focus on to secure their applications.</p>



<h3 class="wp-block-heading">Factors and Claims</h3>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/jflombardo/">Jeff Lombardo</a> and<a href="https://www.linkedin.com/in/ababeanu/"> Alex Babeanu</a> have introduced a new set of claims for the JWT Access Token profile within the OAuth2 standard, along with a new flow. These proposed claims aim to enhance visibility into the Client entity itself. While existing OAuth2 flows provide extensive information about the end-user making requests to access resources (through access or ID token claims), there is little standardization around identifying and assessing the client application that the end-user is authorizing. Specifically, there is no widely accepted way to determine the level of assurance associated with the client entity. For example, how was the client authenticated? Was it a simple ID and secret, mTLS, or a signed JWT assertion? These methods vary significantly in security, with cryptographic signatures offering stronger assurances. Additionally, what security extensions were applied in the OAuth flow? Was PKCE or DPoP used? These factors can impact the overall security posture of a request.</p>



<h3 class="wp-block-heading">Access Control Mechanisms</h3>



<p class="wp-block-paragraph">As access control mechanisms evolve, these considerations are becoming increasingly important. With the rise of AI agents, Policy Decision Points (PDPs) must assess not just the end-user but also the security of the calling application itself. By incorporating these new claims, PDPs can make more informed access control decisions, ensuring stronger and more adaptable security policies.</p>



<p class="wp-block-paragraph">Thus, a better integration with<a href="https://openid.net/wg/authzen/"> AuthZEN</a>-compliant Policy Decision Points (PDP) is proposed in a couple of ways:</p>



<ul class="wp-block-list">
<li>OAuth Authorization Servers (AS) should make direct AuthZEN calls to compliant PDPs as part of their usual token-minting ceremonies. This will supply the PDPs with the additional client claims described above to help in decision-making. (We are thinking in particular about RAR requests, which can be complex authorization requests).<br></li>



<li>The authors also proposed a new Step-Up Authorization Protocol as an extension to<a href="https://www.rfc-editor.org/rfc/rfc9470.html#name-authorization-response"> RFC 9470</a>, Step-Up Authentication Protocol. In this new flow, a Resource Server can request an Authorization Step-Up and require a new set of client claims from the client. The client is then responsible for obtaining these claims by, for example, authenticating using a stronger method (such as mTLS or signed assertions) and ensuring certain extensions (such as DPoP) are presented.</li>
</ul>



<p class="wp-block-paragraph">Work on drafts for these extensions has already started.</p>



<h2 class="wp-block-heading">Closing With a Bang</h2>



<p class="wp-block-paragraph">Finally, as<a href="https://www.linkedin.com/in/selfissued/"> Mike Jones</a> pointed out during his session entitled<a href="https://self-issued.info/?p=2615"> “The Cambrian explosion of OAuth and OpenID Specifications”</a>, there are rather a LOT of standards in the OAuth universe, over 100. So much so that it can be hard for newcomers or implementers to find the right path in this forest. This is nevertheless also a sign of a healthy ecosystem, where more and more problems are tackled. Like the Cambrian explosion that our planet Earth experienced some 540 million years ago, we may be witnessing an explosion in the diversity of Digital Identity topics and concerns, a good sign that we will keep busy for the foreseeable future.</p>



<p class="wp-block-paragraph"><em>Disclaimer: The views expressed in the content are solely those of the author and do not necessarily reflect the views of the IDPro organization.</em></p>



<h2 class="wp-block-heading">Authors:</h2>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="210" height="287" src="https://idpro.org/wp-content/uploads/2025/03/Alex-Babeanu-2025.png" alt="" class="wp-image-2769"/></figure>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/ababeanu/">Alex Babeanu</a> is a seasoned expert with over two decades of building innovative IAM solutions using Graphs and Open Standards, as a principal Engineer, Consultant, Product Manager and CTO. A passionate advocate for the graph-based approach to IAM, Alex has presented at leading conferences and contributed extensively through published papers and blogs. As a founding member of IDPro and part of its editorial committee, Alex plays a key role in curating content for the organization’s monthly publications. Currently, he leads the Access Management product at Indykite, a cutting-edge platform that harnesses graph data and AI to simplify complex identity challenges.</p>



<p class="wp-block-paragraph">Badges: IDPro Member, IDPro Editorial Committee, IDPro BoK Reviewer, IDPro Newsletter Author, IDPro Founding Member</p>



<figure class="wp-block-gallery has-nested-images columns-5 is-cropped wp-block-gallery-2 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="600" height="600" data-id="2272" src="https://idpro.org/wp-content/uploads/2023/06/IDPro_BoK_Badges_R5__Founding_Member.png" alt="" class="wp-image-2272" srcset="https://idpro.org/wp-content/uploads/2023/06/IDPro_BoK_Badges_R5__Founding_Member.png 600w, https://idpro.org/wp-content/uploads/2023/06/IDPro_BoK_Badges_R5__Founding_Member-300x300.png 300w, https://idpro.org/wp-content/uploads/2023/06/IDPro_BoK_Badges_R5__Founding_Member-150x150.png 150w, https://idpro.org/wp-content/uploads/2023/06/IDPro_BoK_Badges_R5__Founding_Member-320x320.png 320w" sizes="auto, (max-width: 600px) 100vw, 600px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="600" height="600" data-id="2436" src="https://idpro.org/wp-content/uploads/2023/11/IDPro_BoK_Badges_R5__Member.png" alt="" class="wp-image-2436" srcset="https://idpro.org/wp-content/uploads/2023/11/IDPro_BoK_Badges_R5__Member.png 600w, https://idpro.org/wp-content/uploads/2023/11/IDPro_BoK_Badges_R5__Member-300x300.png 300w, https://idpro.org/wp-content/uploads/2023/11/IDPro_BoK_Badges_R5__Member-150x150.png 150w, https://idpro.org/wp-content/uploads/2023/11/IDPro_BoK_Badges_R5__Member-320x320.png 320w" sizes="auto, (max-width: 600px) 100vw, 600px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="600" height="600" data-id="2389" src="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Editorial_Committee_Member.png" alt="" class="wp-image-2389" srcset="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Editorial_Committee_Member.png 600w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Editorial_Committee_Member-300x300.png 300w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Editorial_Committee_Member-150x150.png 150w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Editorial_Committee_Member-320x320.png 320w" sizes="auto, (max-width: 600px) 100vw, 600px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="600" height="600" data-id="2390" src="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author.png" alt="" class="wp-image-2390" srcset="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author.png 600w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-300x300.png 300w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-150x150.png 150w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-320x320.png 320w" sizes="auto, (max-width: 600px) 100vw, 600px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="600" height="600" data-id="2391" src="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Active_BoK_Reviewer.png" alt="" class="wp-image-2391" srcset="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Active_BoK_Reviewer.png 600w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Active_BoK_Reviewer-300x300.png 300w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Active_BoK_Reviewer-150x150.png 150w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Active_BoK_Reviewer-320x320.png 320w" sizes="auto, (max-width: 600px) 100vw, 600px" /></figure>
</figure>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="210" height="237" src="https://idpro.org/wp-content/uploads/2025/03/Jeff-Lombardo.png" alt="" class="wp-image-2770"/></figure>



<p class="wp-block-paragraph"><a href="https://www.linkedin.com/in/jflombardo/">Jeff Lombardo</a> is a Solutions Architect expert in IAM, Application Security, and Data Protection. Through 15 years as an IAM consultant for French, Canadian, and US enterprises of all sizes and business verticals, he has delivered innovative solutions with respect to standards and governance frameworks. Since the last 5 years at AWS, he helps organizations enforce best practices and defense in depth for secure cloud adoption.</p>



<figure class="wp-block-gallery has-nested-images columns-4 is-cropped wp-block-gallery-3 is-layout-flex wp-block-gallery-is-layout-flex">
<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="600" height="600" data-id="2436" src="https://idpro.org/wp-content/uploads/2023/11/IDPro_BoK_Badges_R5__Member.png" alt="" class="wp-image-2436" srcset="https://idpro.org/wp-content/uploads/2023/11/IDPro_BoK_Badges_R5__Member.png 600w, https://idpro.org/wp-content/uploads/2023/11/IDPro_BoK_Badges_R5__Member-300x300.png 300w, https://idpro.org/wp-content/uploads/2023/11/IDPro_BoK_Badges_R5__Member-150x150.png 150w, https://idpro.org/wp-content/uploads/2023/11/IDPro_BoK_Badges_R5__Member-320x320.png 320w" sizes="auto, (max-width: 600px) 100vw, 600px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="600" height="600" data-id="2390" src="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author.png" alt="" class="wp-image-2390" srcset="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author.png 600w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-300x300.png 300w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-150x150.png 150w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Newsletter_Author-320x320.png 320w" sizes="auto, (max-width: 600px) 100vw, 600px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="600" height="600" data-id="2391" src="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Active_BoK_Reviewer.png" alt="" class="wp-image-2391" srcset="https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Active_BoK_Reviewer.png 600w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Active_BoK_Reviewer-300x300.png 300w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Active_BoK_Reviewer-150x150.png 150w, https://idpro.org/wp-content/uploads/2023/10/IDPro_BoK_Badges_R5__Active_BoK_Reviewer-320x320.png 320w" sizes="auto, (max-width: 600px) 100vw, 600px" /></figure>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="600" height="600" data-id="1984" src="https://idpro.org/wp-content/uploads/2022/10/BoK-Committee-Badge.png" alt="" class="wp-image-1984" srcset="https://idpro.org/wp-content/uploads/2022/10/BoK-Committee-Badge.png 600w, https://idpro.org/wp-content/uploads/2022/10/BoK-Committee-Badge-300x300.png 300w, https://idpro.org/wp-content/uploads/2022/10/BoK-Committee-Badge-150x150.png 150w, https://idpro.org/wp-content/uploads/2022/10/BoK-Committee-Badge-320x320.png 320w" sizes="auto, (max-width: 600px) 100vw, 600px" /></figure>
</figure>
<p>The post <a href="https://idpro.org/the-oauth-security-workshop-2025/">The OAuth Security Workshop 2025</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Strolling Through RSAC 2022</title>
		<link>https://idpro.org/strolling-through-rsac-2022/</link>
		
		<dc:creator><![CDATA[VTM Web Services]]></dc:creator>
		<pubDate>Fri, 17 Jun 2022 07:46:00 +0000</pubDate>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[conferences]]></category>
		<guid isPermaLink="false">https://idpro.org/?p=1669</guid>

					<description><![CDATA[<p>By Vittorio Bertocci After having attended in person one Identiverse, two EICs, one AuthenticateCon, one IETF, one OSW and one [&#8230;]</p>
<p>The post <a href="https://idpro.org/strolling-through-rsac-2022/">Strolling Through RSAC 2022</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">By Vittorio Bertocci</p>



<p class="wp-block-paragraph">After having attended in person one Identiverse, two EICs, one AuthenticateCon, one IETF, one OSW and one IIW, I thought I definitely left behind the woes of the Lockdown Winter that forced our favorite events to take place in the netherspace that is Zoom or proprietary eponym equivalents. Boy, was I wrong. None of those events prepared me for a conference that takes over entire blocks, where the expo alone is large enough (700+ exhibitors!) to have its own weather system, if not its own zip code. Above all, I wasn’t prepared for an event where you no longer have direct line of sight with your tribe, and the majority of the badge-clad people are perfect strangers.</p>



<p class="wp-block-paragraph">The very distrustful conference site (it asked for my username/password every couple of hours; is this what continuous authentication means?) offered a <a href="https://www.rsaconference.com/usa/agenda/full-agenda">staggering 612 sessions</a>. One first-time attendee asked me &#8211; “how do you choose what to attend at RSA?”. My answer: use the search feature to tease out what’s relevant to your interests. That is also what I have done: as a result, expect this report to be a very partial &amp; personal account of the event. If you want to broaden your perspective, you can chat to other IDPros who were there; you’ll find them on #RSAConference in our IDPro Slack.</p>



<h3 class="wp-block-heading">Content highlights</h3>



<p class="wp-block-paragraph">Despite all the rhetoric about identity being the new perimeter and other platitudes, and <a href="https://twitter.com/vibronet/status/1533944817129951232">some shoutouts to OIDC and FIDO from the keynote</a>, RSAC 2022 had very little content on our favorite topic. The Identity track had 44 sessions, 13 of them being vendor sponsored and 7 being duplicates (overflow rooms).&nbsp;</p>



<p class="wp-block-paragraph">While zero trust was still one of the dominating buzzwords, I was surprised to see that a search for “blockchain” only returned 5 sessions, “web3” exactly zero, and “decentralized” only one track session, from IDPro’s very own <a href="https://twitter.com/gffletch">George Fletcher</a>.</p>



<p class="wp-block-paragraph"><a href="https://www.rsaconference.com/usa/agenda/session/Managing%20De-Centralized%20Identities%20A%20Relying%20Party%20Perspective">George’s session, “Managing De-Centralized Identities: A Relying Party Perspective”</a>,&nbsp; was one of the highlights of the conference for me. The first time I saw George present on this topic was at an IIW in 2019. In a nutshell, the session takes tools and principles of Self-Sovereign Identity (SSI)/decentralized identity and tries to apply them when developing a realistic relying party. In so doing, he uncovers discrepancies, opportunities and impedance mismatch that are both a powerful tool to understand SSI’s value proposition and an honest litmus test to assess the maturity level of those new technologies. TL;DR: things did improve since that first 2019 session, but much still needs to be figured out for those technologies to be viable in real world use.&nbsp;</p>



<p class="wp-block-paragraph"><br>After the session, a bunch of <a href="https://twitter.com/gffletch/status/1534698986228961280">IDPros and identirati congregated right outside</a>, engaging in an incredibly satisfying 30 minute long discussion on VCs, passkeys and their potential impact on society. Those 30 minutes alone were worth the trip, what a JOY to be among one’s people!&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Passkeys were the centerpiece of the other awesome event-in-the-event I had the chance to attend, the <a href="https://www.rsaconference.com/usa/agenda/session/FIDO%20Alliance%20Passwordless%20Future%20Is%20Here%20Isnt%20It%20Seminar">half-day FIDO Alliance seminar</a> on &#8211; surprise surprise &#8211; passwordless and passkeys in particular. The Apple WWDC announcements about passkeys created a huge interest around the topic, and the seminar was the perfect opportunity to demystify the technology and get a glimpse of the enormous potential it has to finally deliver a substantial blow to passwords in consumer authentication. Our very own IDPro member <a href="https://twitter.com/timcappalli">Tim Cappalli</a> delivered key parts of the event, from the <a href="https://twitter.com/vibronet/status/1534289513815543808">very first live cross device/vendor passkey demo</a> to a <a href="https://twitter.com/vibronet/status/1534300647230648320">very lively panel</a>.&nbsp;&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Remaining in IDpro territory, mighty board member and <a href="https://www.amazon.com/Implementing-Identity-Management-AWS-environments/dp/1800562284/">acclaimed book author</a> <a href="https://twitter.com/jonlehtinen">Jon Lehtinen</a> presented a session on “<a href="https://www.rsaconference.com/usa/agenda/session/Demystifying%20the%20Identity%20Capabilities%20of%20AWS%20for%20Enterprise%20Practitioners">Demystifying the Identity Capabilities of AWS for Enterprise Practitioners</a>”- no one will be surprised to learn that it was well received.</p>



<p class="wp-block-paragraph">Just because it’s RSA, and the RSA experience needs some “pure security” to be complete, I decided to attend “<a href="https://www.rsaconference.com/usa/agenda/session/Bypassing%20Windows%20Hello%20for%20Business%20and%20Pleasure">Bypassing Windows Hello for Business and Pleasure</a>” &#8211;&nbsp; and I wasn’t disappointed. The lengths to which the researcher had to go in order to defeat Windows Hello were substantial, and he presented his journey with flair and competence. If you have access to the on-demand content, I would recommend this session.</p>



<h3 class="wp-block-heading">In Summary</h3>



<p class="wp-block-paragraph">Is RSA still worth the very hefty admission price? From the content perspective, I am honestly not sure. I got lucky with George and passkey, but the dearth of identity content is concerning, though I suspect part of the fault falls on ourselves &#8211; I personally had some submission fatigue and didn’t propose anything. Perhaps we should resolve to submit in bigger numbers and see whether we move the needle. From the experience perspective… I’d say it’s a resounding YES. True, we identirati have other opportunities to see each other, but with its sheer size, parties (<a href="https://twitter.com/vibronet/status/1536463513077440512?s=20&amp;t=G91ktcFBKIzPd6kgAuG4IQ">rrrisky</a>) and general vibe, RSA remains an important milestone in the conference calendar, and I am glad it’s back!</p>



<figure class="wp-block-image size-full is-resized"><img loading="lazy" decoding="async" src="https://idpro.org/wp-content/uploads/2022/06/Vittorio-Bertocci-Picture.png" alt="" class="wp-image-1679" width="829" height="302" srcset="https://idpro.org/wp-content/uploads/2022/06/Vittorio-Bertocci-Picture.png 789w, https://idpro.org/wp-content/uploads/2022/06/Vittorio-Bertocci-Picture-300x109.png 300w, https://idpro.org/wp-content/uploads/2022/06/Vittorio-Bertocci-Picture-768x279.png 768w" sizes="auto, (max-width: 829px) 100vw, 829px" /></figure>



<p class="wp-block-paragraph"><strong>About the Author</strong></p>



<p class="wp-block-paragraph">Vittorio Bertocci is a Principal Architect for Auth0|OKTA. A veteran of the identity industry, in his 20 year career Vittorio helped create, shape and steer key identity products, technologies, and practices. Vittorio is currently serving on the OpenID Foundation board of directors, and is the host of the <a href="https://identityunlocked.auth0.com/public/49/Identity%2C-Unlocked.--bed7fada"><em>Identity, Unlocked</em></a> podcast. An active member of the identity community, Vittorio is a well-known speaker, educator, and published author.</p>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="820" height="221" src="https://idpro.org/wp-content/uploads/2022/06/Vittorio-Badges.png" alt="" class="wp-image-1681" srcset="https://idpro.org/wp-content/uploads/2022/06/Vittorio-Badges.png 820w, https://idpro.org/wp-content/uploads/2022/06/Vittorio-Badges-300x81.png 300w, https://idpro.org/wp-content/uploads/2022/06/Vittorio-Badges-768x207.png 768w" sizes="auto, (max-width: 820px) 100vw, 820px" /></figure>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://idpro.org/strolling-through-rsac-2022/">Strolling Through RSAC 2022</a> appeared first on <a href="https://idpro.org">IDPro</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>

<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/?utm_source=w3tc&utm_medium=footer_comment&utm_campaign=free_plugin

Page Caching using Disk: Enhanced 
Lazy Loading (feed)
Minified using Disk

Served from: idpro.org @ 2026-09-06 15:35:35 by W3 Total Cache
-->