Feb. 20, 2024, 5:46 p.m. | Black Hat

Black Hat www.youtube.com

Although x509 certificates have been here for a while, they have become more popular for client authentication in zero-trust networks in recent years. Mutual TLS, or authentication based on X509 certificates in general, brings advantages compared to passwords or tokens, but you get increased complexity in return.

In this talk, we'll deep dive into some novel attacks on mTLS authentication....

By: Michael Stepankin

Full Abstract and Presentation Materials: https://www.blackhat.com/us-23/briefings/schedule/#mtls-when-certificate-authentication-is-done-wrong-33203

authentication certificate certificates client complexity deep dive dive general mtls mutual tls networks passwords popular return tls tokens trust wrong

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Associate Compliance Advisor

@ SAP | Budapest, HU, 1031

DevSecOps Engineer

@ Qube Research & Technologies | London

Software Engineer, Security

@ Render | San Francisco, CA or Remote (USA & Canada)

Associate Consultant

@ Control Risks | Frankfurt, Hessen, Germany

Senior Security Engineer

@ Activision Blizzard | Work from Home - CA