Skip to content
Carolina Code Conference
Served by Pony (Stallion) in 22ms

2024 speaker

Tim Tomes

Tim Tomes

Founder and Application Security Engineer, PractiSec

PractiSec

Greenville, SC

Tim is an Application Security Professional with over 30 years of experience in the information technology and security industries. From network architecture design to software development to full-scope penetration testing, Tim has worked in multiple disciplines as both a manager and technician for the United States Military and private industry. Now focusing exclusively on web applications, Tim hones his development and security skills through managing multiple Open Source software projects, conducting consultative engagements, and providing training through PractiSec, a company for which he is also the founder. Tim has a strong belief in contributing to the community and does so through writing technical articles, speaking at conferences, and mentoring the next generation of web application security professionals.

Visit website

2024 · keynote

{JWT}.{Misuse}.&Abuse

JWTs are an incredibly flexible tool that make life easier for developers because they are standardized, widely supported, and include important security features by default. However, like any powerful tool, JWTs can be dangerous when used incorrectly, or for unintended purposes. In this talk, I aim to shine a light on common JWT misuse and abuse. I'll start by briefly describing JWTs and common use cases for them. I'll then present real world scenarios of misuse and abuse from applications that I've tested as a consultant, and written as an engineer. As I present each scenario, I'll demonstrate the various features and failures live, and discuss how the specific implementation of JWTs can be hardened. The end result will be an enlightening and entertaining presentation of information and experience that will provide the viewer with a practical knowledge of how, and how not, to use JWTs.

From the talk