Security Meetup @ Connectory by Bosch

Connectory Stuttgart - Powered by Robert Bosch GmbH, 78 Königstraße, Stuttgart, 70173

GDG Stuttgart

Being invited to the Connectory by Bosch we will have an evening filled with discussion about Security in Software Development.

Apr 3, 4:00 – 8:00 PM (UTC)

7 RSVP'd

RSVP

Key Themes

AngularCloudWeb

About this event

Application Security has never been more relevant than in current times!

We will have two experts speaking about how we can improve security of our applications:


Martina Kraus (Kraus IT Consulting)

Protect your frontend: Why tokens in the browser are a bad idea

As frontend developers, we want to create smooth, user-friendly experiences, but security often takes a back seat to functionality. In this talk, we'll dive into JSON Web Tokens (JWTs) and why storing them in the frontend is a recipe for disaster. Using some real-world examples, we'll explore the risks of this practice, from token theft to session hijacking. As a solution, we will discuss the principles of the backend-for-frontend (BFF) model and how it can prevent your application from becoming a playground for hackers. By the end of this session, you will not only be convinced to keep JWTs out of your frontend, but you will also be equipped with practical strategies to improve your app's security without compromising performance.


Andreas Falk (Novatec Consulting)

OAuth 2.1 & OpenID Connect in Action: What’s New, What’s Secure, and What You Need to Know

OAuth 2.1 and OpenID Connect are the cornerstones of modern authentication and authorization, securing APIs and web applications across the internet. This talk provides a practical introduction to OAuth 2.1, the latest evolution of the OAuth framework, and OpenID Connect, the identity layer built on top of it. We’ll explore key concepts such as authorization flows, tokens, and scopes, while also diving into the latest security enhancements, including the recently published RFC 9700 (Best Current Practice for OAuth 2.0 Security), which updates and extends the threat model and latest security advice. Through live demos, we’ll look at secure OAuth 2.1 flows, OpenID Connect authentication, best practices like PKCE, and refresh token rotation.


And of course there will be Drinks and Pizza between the talks :)

When

When

Thursday, April 3, 2025
4:00 PM – 8:00 PM (UTC)

Agenda

4:00 PMIntro
4:30 PMMartina Kraus - Protect your frontend: Why tokens in the browser are a bad idea
5:15 PMPizza & Drinks
5:45 PMAndreas Falk - OAuth 2.1 & OpenID Connect in Action: What’s New, What’s Secure, and What You Need to Know

Speakers

  • Martina Kraus

    GDE Angular

  • Andreas Falk

    Novatec Consulting GmbH

    Senior Managing Consultant, Lead of Security

Partner

Stuttgart Connectory by Robert Bosch GmbH logo

Stuttgart Connectory by Robert Bosch GmbH

Organizers

  • Marcel Bagemihl

    Novatec Consulting GmbH

    GDG Organizer

  • Sebastian Graef

    Novatec Consulting GmbH

    GDG Organizer

  • Sebastian Harner

    Novatec Consulting GmbH

    Senior Software Engineer

  • Miriam Becker

    Novatec Consulting GmbH

  • Nina Kast

    Xiting

    Software Engineer

Contact Us