What is OAuth and why does it matter? - OAuth in Five Minutes

Sdílet
Vložit
  • čas přidán 20. 01. 2020
  • In this video we cover what OAuth is and why we even have it in the first place. OAuth in Five Minutes is a series where we deep-dive on various topics around OAuth in just five minutes!
    Buy the book! amzn.to/2S6Uj4e
    Check out our video course! The Nuts and Bolts of OAuth 2.0
    oauth2simplified.com/course
    Learn more about OAuth at oauth.net
    --
    Okta is a developer API service that stores user accounts for your web apps, mobile apps, and APIs.
    * Sign up for Okta for free at developer.okta.com/signup/
    * For more info visit us at developer.okta.com/
    * Developer Blog: developer.okta.com/blog/
    * Sign up for our monthly newsletter! a0.to/zeroindex
    * Follow us on Twitter: / oktadev
    * Follow us on FB: / oktadevelopers
    * Follow us on LinkedIn: / oktadev
  • Věda a technologie

Komentáře • 77

  • @jojojawjaw
    @jojojawjaw Před rokem +33

    I don't think I've ever seen a tutorial this informative, clear, and helpful before!

  • @WittCode
    @WittCode Před 2 lety +29

    I got more out of this 5 minute video than reading a ton of articles! Thanks so much!

  • @ip2design
    @ip2design Před 4 lety +42

    A very clear and helpful introduction. Thanks for shooting this video

  • @joshbrolicwright
    @joshbrolicwright Před 4 měsíci +1

    Thank you for keeping it simple and to the point!

  • @charlesbevitt6727
    @charlesbevitt6727 Před 3 lety +13

    I’ve been wondering why the heck anyone would want to use OAuth in a strictly first party situation. You really explained it well and I’m finally convinced. Big thanks for a great video.

    • @charlesopuoro5295
      @charlesopuoro5295 Před rokem +1

      Absolutely!!! Same. He sure did. It reduced the Attack Surface Area as explained.

  • @fijaisonjd
    @fijaisonjd Před 4 lety +17

    Good explanation. Background music is a bit distracting.

    • @Julian-tf8nj
      @Julian-tf8nj Před 3 lety +4

      yeah, I kept saying "what the heck is that noise??"

  • @user-zw6ws5df6x
    @user-zw6ws5df6x Před 2 lety +2

    This is the best introduction video for OAuth concepts. Thank you for the material.

  • @francisrafal
    @francisrafal Před 3 lety +5

    Thank you, that explanation was exactly what I was looking for!

  • @ericdavid890
    @ericdavid890 Před 4 lety +11

    Just getting acquainted with oauth and this is a great intro!

  • @shashvatshukla
    @shashvatshukla Před rokem

    You made the world a better place by making this video.

  • @candiceerasmus5943
    @candiceerasmus5943 Před 3 lety +5

    I am extremely green in this space - this was such an amazing introduction to OAuth for me. Thank you thank you thank you

  • @manjotsinghjuneja217
    @manjotsinghjuneja217 Před rokem

    the best 5 minutes of my entire day, thank you!

  • @ryanjohnson4566
    @ryanjohnson4566 Před 2 lety +3

    Thanks, great to get a good human explanation. These things are not that complicated, but all the new terms that are introduced muddy the waters for me. Your explanation is excellent.

  • @sachinmankotia2291
    @sachinmankotia2291 Před 2 lety +3

    Simple and clear explanation. I have used oauth before in my projects, but to be honest, I learnt its exact flow today :)

  • @charlesopuoro5295
    @charlesopuoro5295 Před rokem +1

    Thanks a whole lot for this video. It served its intended purpose.

  • @pavanamancherla5039
    @pavanamancherla5039 Před 4 lety +5

    Nicely explained. Appreciate your efforts

  • @AsifChauhan
    @AsifChauhan Před 4 lety +5

    Very interesting point about companies' internal 1st part apps using OAuth as Authentication vs just for Authorization👌

  • @alexandermoeller5299
    @alexandermoeller5299 Před 4 lety +3

    great explanation! Thanks for the video

  • @user-or7ji5hv8y
    @user-or7ji5hv8y Před 2 lety +1

    Concise and well explained.

  • @danielelmuneco1994
    @danielelmuneco1994 Před 4 lety +3

    Wow! Very clear.
    Thank you :)

  • @dsulvadarius
    @dsulvadarius Před 3 lety

    Wow! Beautifully explained.

  • @alexshmalex
    @alexshmalex Před 11 měsíci

    Epic. Super helpful, thanks for posting.

  • @cloudguy4192
    @cloudguy4192 Před 3 lety

    Thank you for posting the video!

  • @venky76v
    @venky76v Před 4 lety +1

    Awesome video tutorial guys ✌️✌️

  • @KDOERAK
    @KDOERAK Před 3 lety

    a great talk: thx and keep them coming!

  • @AlphyGacheru
    @AlphyGacheru Před 3 lety +1

    Very useful, thank you!

  • @gauravvarma3645
    @gauravvarma3645 Před rokem

    Super insightful, thanks

  • @abhinavraut3099
    @abhinavraut3099 Před 3 lety

    very clear thanks!

  • @mnite3842
    @mnite3842 Před 3 lety

    One word - Awesome!!!!

  • @befit_kw7762
    @befit_kw7762 Před 4 lety +5

    Graphical representation would be extremely beneficial. Great work👍
    We need tutorials on Google fit api as well as other APIs..
    Thanks

    • @bdemers
      @bdemers Před 4 lety +2

      How about this one! developer.okta.com/blog/2019/10/21/illustrated-guide-to-oauth-and-oidc

  • @Cowglow
    @Cowglow Před 4 lety

    !!! awesome video!

  • @JJovich
    @JJovich Před 4 lety

    Thanks great video

  • @RajanieshKaushikk
    @RajanieshKaushikk Před 3 lety +1

    very nice video!!

  • @harikrishnareddym
    @harikrishnareddym Před 2 lety

    Wow..Brilliant... too good... and all other good superlatives here.... :) ... thank you

  • @jims2507
    @jims2507 Před 3 lety

    Thank you! I never understood giving up my twitter password to another website for authentication, but I see that option ALL the time.

  • @JACKSONANTO
    @JACKSONANTO Před rokem

    Really good one

  • @johnhack67
    @johnhack67 Před 3 lety +1

    thanks

  • @WhiteSiroi
    @WhiteSiroi Před rokem

    thank you

  • @chologhuribangladesh7792

    very helpful, described video. Like oAuth101.

  • @barzanahmed7194
    @barzanahmed7194 Před 3 lety

    OAuth IS AWESOME!!!

  • @shilpashravge8083
    @shilpashravge8083 Před rokem +1

    Thanks !!

  • @NYYstateofmind
    @NYYstateofmind Před 2 lety +2

    Why is sms mfa insecure?
    Also, when you rely on Google for Oauth are you sharing application specific data? Or does Google only know that you use that service and when you log in

    • @-Ncrypt
      @-Ncrypt Před rokem

      SMS MFA is prone to SIM swap attacks. An attacker can also break into the cellular network and intercept SMS messages to your phone. However, it's still better to have SMS MFA on than no MFA at all.

  • @zaimcodes
    @zaimcodes Před 2 lety

    Basically, OAuth is a protocol that redirects user from the 3rd party application and authenticate themselves through the OAuth server (I got confused here so Google, Twitter, and other trusted applications have their own OAuth server?) while having the ability to understand what data the 3rd party application able and unable to access, right?
    3:30 basically SSO isn't it? So, OAuth protocol allows 3rd party application (external) to access data/API of the trusted application securely while SSO allows the user to access various services of the same application (internal) without needing to login over and over again, isn't it?

  • @randommode3016
    @randommode3016 Před 3 lety

    4:47 reasons why you should use OAuth for everything

  • @gamerrana786
    @gamerrana786 Před měsícem

    how can we make our own? If we have our own brand

  • @greendsnow
    @greendsnow Před 2 lety

    what if they're working for an Intelligence Office?

  • @sufyanshoaib
    @sufyanshoaib Před 4 lety +1

    awesome.. thanks... just need to slowdown a bit ...

    • @aaronpk
      @aaronpk Před 4 lety +5

      If I do that, then people are just gonna complain that I talk too slow!

    • @sufyanshoaib
      @sufyanshoaib Před 4 lety

      @@aaronpk I am happy in both cases ... :) :+1:

    • @mikexue5104
      @mikexue5104 Před 3 lety

      me too. but it only means i need improve my listening skills.

  • @williamroncallo7926
    @williamroncallo7926 Před rokem

    I have seen his videos before, and have always been confused on something… I understand why he says third-party applications, when saying Oauth was created for accessing them from the client applications, so that the client application doesn’t have to ask the user for the password, but why does he call client applications first party? What is a second party application then?

    • @taraleseena5321
      @taraleseena5321 Před rokem

      Yelp is third party.. for the app resource (Yelp content), they are also first party. Unfortunately, they want your Google password, for which they are a third party between you and Google)

  • @ChrisAthanas
    @ChrisAthanas Před rokem

    Rather than hand waving, and use of “the app”, why not give us some images so it’s very clear and not confusing

  • @randommode3016
    @randommode3016 Před 3 lety

    4:18 people makes mistakes so true 🙈

  • @muchirajunior9751
    @muchirajunior9751 Před rokem

    why should we not use messages multi factor auth

    • @OktaDev
      @OktaDev  Před rokem

      Hello, thanks for your question. Could you expand a bit more on what you mean by messages for MFA, please? Thanks!

    • @muchirajunior9751
      @muchirajunior9751 Před rokem

      @@OktaDev on the video you said its a bad idea to use messages for MFA

  • @ballsxan
    @ballsxan Před 4 lety

    ¿A qué clase de cerebrito se le ocurrió presentar información técnica en vídeo?

  • @byzantinethrive
    @byzantinethrive Před 3 lety

    What happened to Justin

  • @vuufke4327
    @vuufke4327 Před 2 lety

    when is the last time you blinked?

  • @randommode3016
    @randommode3016 Před 3 lety

    4:19 lol when you discover that your application has logging password in a text file for months (? 🤣 I hope that never happens🙏 let's use OAuth

  • @croooaaalagraula
    @croooaaalagraula Před 4 lety

    Good explanation, only guy speaks too fast for majority of audience, and would have been great to have some graphics illustrating his explanations.

  • @ilgioa
    @ilgioa Před 2 lety

    The background music is quite distracting.

  • @ThePrachi19
    @ThePrachi19 Před rokem

    Nice explanation… but Next time please remove the BGM when you are explaining, I could hardly concentrate😢

  • @AntonioEugenioVida
    @AntonioEugenioVida Před rokem

    tante ciacoe

  • @toohype8762
    @toohype8762 Před 2 lety

    Oh yeas, lets put one monolith point of failure in our application and let google run it. I'm sure they're doing this out of the goodness of their heart. Also if you want any support better hope the community addresses it cuz google corporate wilil not give AF. Better hope the project manager doesn't get promoted then google depreciates the service cuz no one wants to maintain code they want to create fancy products looking for a problem.

    • @aaronpk
      @aaronpk Před 2 lety

      To be clear, Google in this example is providing a service to Google itself.

  • @Samikhadris
    @Samikhadris Před 5 měsíci

    Samikhadris

  • @taraleseena5321
    @taraleseena5321 Před rokem

    Would help if you speak 50 words per minute instead of 200

  • @pradeepkumarreddykondreddy7048

    too fast

  • @darkpill
    @darkpill Před 3 lety

    You repeat yourself a lot. Video could have been 2:30