What is OAuth and why does it matter? - OAuth in Five Minutes

แชร์
ฝัง
  • เผยแพร่เมื่อ 20 ม.ค. 2020
  • In this video we cover what OAuth is and why we even have it in the first place. OAuth in Five Minutes is a series where we deep-dive on various topics around OAuth in just five minutes!
    Buy the book! amzn.to/2S6Uj4e
    Check out our video course! The Nuts and Bolts of OAuth 2.0
    oauth2simplified.com/course
    Learn more about OAuth at oauth.net
    --
    Okta is a developer API service that stores user accounts for your web apps, mobile apps, and APIs.
    * Sign up for Okta for free at developer.okta.com/signup/
    * For more info visit us at developer.okta.com/
    * Developer Blog: developer.okta.com/blog/
    * Sign up for our monthly newsletter! a0.to/zeroindex
    * Follow us on Twitter: / oktadev
    * Follow us on FB: / oktadevelopers
    * Follow us on LinkedIn: / oktadev
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 77

  • @jojojawjaw
    @jojojawjaw ปีที่แล้ว +32

    I don't think I've ever seen a tutorial this informative, clear, and helpful before!

  • @WittCode
    @WittCode 2 ปีที่แล้ว +29

    I got more out of this 5 minute video than reading a ton of articles! Thanks so much!

  • @ip2design
    @ip2design 4 ปีที่แล้ว +42

    A very clear and helpful introduction. Thanks for shooting this video

  • @charlesbevitt6727
    @charlesbevitt6727 3 ปีที่แล้ว +13

    I’ve been wondering why the heck anyone would want to use OAuth in a strictly first party situation. You really explained it well and I’m finally convinced. Big thanks for a great video.

    • @charlesopuoro5295
      @charlesopuoro5295 ปีที่แล้ว +1

      Absolutely!!! Same. He sure did. It reduced the Attack Surface Area as explained.

  • @joshbrolicwright
    @joshbrolicwright 4 หลายเดือนก่อน +1

    Thank you for keeping it simple and to the point!

  • @fijaisonjd
    @fijaisonjd 4 ปีที่แล้ว +17

    Good explanation. Background music is a bit distracting.

    • @Julian-tf8nj
      @Julian-tf8nj 3 ปีที่แล้ว +4

      yeah, I kept saying "what the heck is that noise??"

  • @francisrafal
    @francisrafal 3 ปีที่แล้ว +5

    Thank you, that explanation was exactly what I was looking for!

  • @user-zw6ws5df6x
    @user-zw6ws5df6x 2 ปีที่แล้ว +2

    This is the best introduction video for OAuth concepts. Thank you for the material.

  • @sachinmankotia2291
    @sachinmankotia2291 2 ปีที่แล้ว +3

    Simple and clear explanation. I have used oauth before in my projects, but to be honest, I learnt its exact flow today :)

  • @ryanjohnson4566
    @ryanjohnson4566 2 ปีที่แล้ว +3

    Thanks, great to get a good human explanation. These things are not that complicated, but all the new terms that are introduced muddy the waters for me. Your explanation is excellent.

  • @AsifChauhan
    @AsifChauhan 4 ปีที่แล้ว +5

    Very interesting point about companies' internal 1st part apps using OAuth as Authentication vs just for Authorization👌

  • @pavanamancherla5039
    @pavanamancherla5039 4 ปีที่แล้ว +5

    Nicely explained. Appreciate your efforts

  • @alexandermoeller5299
    @alexandermoeller5299 4 ปีที่แล้ว +3

    great explanation! Thanks for the video

  • @manjotsinghjuneja217
    @manjotsinghjuneja217 ปีที่แล้ว

    the best 5 minutes of my entire day, thank you!

  • @ericdavid890
    @ericdavid890 3 ปีที่แล้ว +11

    Just getting acquainted with oauth and this is a great intro!

  • @user-or7ji5hv8y
    @user-or7ji5hv8y 2 ปีที่แล้ว +1

    Concise and well explained.

  • @danielelmuneco1994
    @danielelmuneco1994 4 ปีที่แล้ว +3

    Wow! Very clear.
    Thank you :)

  • @candiceerasmus5943
    @candiceerasmus5943 3 ปีที่แล้ว +5

    I am extremely green in this space - this was such an amazing introduction to OAuth for me. Thank you thank you thank you

  • @dsulvadarius
    @dsulvadarius 3 ปีที่แล้ว

    Wow! Beautifully explained.

  • @shashvatshukla
    @shashvatshukla ปีที่แล้ว

    You made the world a better place by making this video.

  • @venky76v
    @venky76v 4 ปีที่แล้ว +1

    Awesome video tutorial guys ✌️✌️

  • @charlesopuoro5295
    @charlesopuoro5295 ปีที่แล้ว +1

    Thanks a whole lot for this video. It served its intended purpose.

  • @AlphyGacheru
    @AlphyGacheru 3 ปีที่แล้ว +1

    Very useful, thank you!

  • @gauravvarma3645
    @gauravvarma3645 ปีที่แล้ว

    Super insightful, thanks

  • @alexshmalex
    @alexshmalex 11 หลายเดือนก่อน

    Epic. Super helpful, thanks for posting.

  • @KDOERAK
    @KDOERAK 3 ปีที่แล้ว

    a great talk: thx and keep them coming!

  • @cloudguy4192
    @cloudguy4192 3 ปีที่แล้ว

    Thank you for posting the video!

  • @abhinavraut3099
    @abhinavraut3099 3 ปีที่แล้ว

    very clear thanks!

  • @befit_kw7762
    @befit_kw7762 4 ปีที่แล้ว +5

    Graphical representation would be extremely beneficial. Great work👍
    We need tutorials on Google fit api as well as other APIs..
    Thanks

    • @bdemers
      @bdemers 4 ปีที่แล้ว +2

      How about this one! developer.okta.com/blog/2019/10/21/illustrated-guide-to-oauth-and-oidc

  • @mnite3842
    @mnite3842 3 ปีที่แล้ว

    One word - Awesome!!!!

  • @RajanieshKaushikk
    @RajanieshKaushikk 3 ปีที่แล้ว +1

    very nice video!!

  • @jims2507
    @jims2507 3 ปีที่แล้ว

    Thank you! I never understood giving up my twitter password to another website for authentication, but I see that option ALL the time.

  • @JACKSONANTO
    @JACKSONANTO ปีที่แล้ว

    Really good one

  • @JJovich
    @JJovich 4 ปีที่แล้ว

    Thanks great video

  • @harikrishnareddym
    @harikrishnareddym 2 ปีที่แล้ว

    Wow..Brilliant... too good... and all other good superlatives here.... :) ... thank you

  • @Cowglow
    @Cowglow 4 ปีที่แล้ว

    !!! awesome video!

  • @barzanahmed7194
    @barzanahmed7194 3 ปีที่แล้ว

    OAuth IS AWESOME!!!

  • @johnhack67
    @johnhack67 3 ปีที่แล้ว +1

    thanks

  • @WhiteSiroi
    @WhiteSiroi ปีที่แล้ว

    thank you

  • @shilpashravge8083
    @shilpashravge8083 ปีที่แล้ว +1

    Thanks !!

    • @OktaDev
      @OktaDev  ปีที่แล้ว

      Welcome!

  • @chologhuribangladesh7792
    @chologhuribangladesh7792 ปีที่แล้ว

    very helpful, described video. Like oAuth101.

  • @NYYstateofmind
    @NYYstateofmind 2 ปีที่แล้ว +2

    Why is sms mfa insecure?
    Also, when you rely on Google for Oauth are you sharing application specific data? Or does Google only know that you use that service and when you log in

    • @-Ncrypt
      @-Ncrypt ปีที่แล้ว

      SMS MFA is prone to SIM swap attacks. An attacker can also break into the cellular network and intercept SMS messages to your phone. However, it's still better to have SMS MFA on than no MFA at all.

  • @randommode3016
    @randommode3016 3 ปีที่แล้ว

    4:47 reasons why you should use OAuth for everything

  • @zaimcodes
    @zaimcodes 2 ปีที่แล้ว

    Basically, OAuth is a protocol that redirects user from the 3rd party application and authenticate themselves through the OAuth server (I got confused here so Google, Twitter, and other trusted applications have their own OAuth server?) while having the ability to understand what data the 3rd party application able and unable to access, right?
    3:30 basically SSO isn't it? So, OAuth protocol allows 3rd party application (external) to access data/API of the trusted application securely while SSO allows the user to access various services of the same application (internal) without needing to login over and over again, isn't it?

  • @sufyanshoaib
    @sufyanshoaib 4 ปีที่แล้ว +1

    awesome.. thanks... just need to slowdown a bit ...

    • @aaronpk
      @aaronpk 4 ปีที่แล้ว +5

      If I do that, then people are just gonna complain that I talk too slow!

    • @sufyanshoaib
      @sufyanshoaib 4 ปีที่แล้ว

      @@aaronpk I am happy in both cases ... :) :+1:

    • @mikexue5104
      @mikexue5104 3 ปีที่แล้ว

      me too. but it only means i need improve my listening skills.

  • @gamerrana786
    @gamerrana786 20 วันที่ผ่านมา

    how can we make our own? If we have our own brand

  • @randommode3016
    @randommode3016 3 ปีที่แล้ว

    4:18 people makes mistakes so true 🙈

  • @greendsnow
    @greendsnow 2 ปีที่แล้ว

    what if they're working for an Intelligence Office?

  • @williamroncallo7926
    @williamroncallo7926 ปีที่แล้ว

    I have seen his videos before, and have always been confused on something… I understand why he says third-party applications, when saying Oauth was created for accessing them from the client applications, so that the client application doesn’t have to ask the user for the password, but why does he call client applications first party? What is a second party application then?

    • @taraleseena5321
      @taraleseena5321 ปีที่แล้ว

      Yelp is third party.. for the app resource (Yelp content), they are also first party. Unfortunately, they want your Google password, for which they are a third party between you and Google)

  • @ChrisAthanas
    @ChrisAthanas ปีที่แล้ว

    Rather than hand waving, and use of “the app”, why not give us some images so it’s very clear and not confusing

  • @muchirajunior9751
    @muchirajunior9751 ปีที่แล้ว

    why should we not use messages multi factor auth

    • @OktaDev
      @OktaDev  ปีที่แล้ว

      Hello, thanks for your question. Could you expand a bit more on what you mean by messages for MFA, please? Thanks!

    • @muchirajunior9751
      @muchirajunior9751 ปีที่แล้ว

      @@OktaDev on the video you said its a bad idea to use messages for MFA

  • @ballsxan
    @ballsxan 4 ปีที่แล้ว

    ¿A qué clase de cerebrito se le ocurrió presentar información técnica en vídeo?

  • @croooaaalagraula
    @croooaaalagraula 4 ปีที่แล้ว

    Good explanation, only guy speaks too fast for majority of audience, and would have been great to have some graphics illustrating his explanations.

  • @ThePrachi19
    @ThePrachi19 ปีที่แล้ว

    Nice explanation… but Next time please remove the BGM when you are explaining, I could hardly concentrate😢

  • @randommode3016
    @randommode3016 3 ปีที่แล้ว

    4:19 lol when you discover that your application has logging password in a text file for months (? 🤣 I hope that never happens🙏 let's use OAuth

  • @byzantinethrive
    @byzantinethrive 3 ปีที่แล้ว

    What happened to Justin

  • @vuufke4327
    @vuufke4327 2 ปีที่แล้ว

    when is the last time you blinked?

  • @AntonioEugenioVida
    @AntonioEugenioVida ปีที่แล้ว

    tante ciacoe

  • @ilgioa
    @ilgioa 2 ปีที่แล้ว

    The background music is quite distracting.

  • @toohype8762
    @toohype8762 2 ปีที่แล้ว

    Oh yeas, lets put one monolith point of failure in our application and let google run it. I'm sure they're doing this out of the goodness of their heart. Also if you want any support better hope the community addresses it cuz google corporate wilil not give AF. Better hope the project manager doesn't get promoted then google depreciates the service cuz no one wants to maintain code they want to create fancy products looking for a problem.

    • @aaronpk
      @aaronpk 2 ปีที่แล้ว

      To be clear, Google in this example is providing a service to Google itself.

  • @Samikhadris
    @Samikhadris 4 หลายเดือนก่อน

    Samikhadris

  • @taraleseena5321
    @taraleseena5321 ปีที่แล้ว

    Would help if you speak 50 words per minute instead of 200

  • @pradeepkumarreddykondreddy7048
    @pradeepkumarreddykondreddy7048 2 ปีที่แล้ว +2

    too fast

  • @darkpill
    @darkpill 3 ปีที่แล้ว

    You repeat yourself a lot. Video could have been 2:30