Habr•September 8, 2026•🇷🇺Translated from Russian

redb.Identity Deploys Three-Layer Defense to Neutralize Stolen Access Tokens in OpenID Connect

redb.Identity, a custom OAuth 2.1 / OpenID Connect provider developed on .NET, tackles the problem of stolen access tokens with three concrete layers of defense rather than relying on declarative statements. Bearer tokens work for whoever possesses them, allowing an attacker who extracts a token via XSS, a compromised npm package, browser extension, or localStorage to operate from any machine until expiration, typically fifteen minutes to one hour.

Origin of Token Theft

Token theft commonly stems from XSS in the application itself, XSS through a dependency where a compromised npm package gains the same DOM and network access as first-party code, malicious browser extensions, or direct reads from localStorage. All four vectors allow the attacker to carry away the token itself, eliminating any need for the victim’s browser, network, or session.

Layer One: Preventing Theft with BFF

Most identity-server admin consoles, including Keycloak and WSO2 Identity Server, run as public OAuth clients in the browser and therefore store administrator access tokens in JavaScript-accessible memory. redb.Identity.Web instead uses Blazor Server with cookie authentication. Tokens are stored on the authentication ticket via AuthenticationTokenExtensions.StoreTokens and retrieved server-side with GetTokenAsync. All intermediate states such as MFA challenges and consent screens are likewise held in HttpOnly, SameSite=Lax, Secure cookies protected by Data Protection. Because markup renders on the server and only a SignalR diff reaches the browser, no JavaScript bundle holds application state.

BFF converts a silent compromise from another country into an active session inside the victim’s browser only while the page remains open. It therefore trades one detection signal (impossible travel) for a smaller blast radius, but still requires behavioral monitoring.

Layer Two: Rendering Stolen Tokens Useless with DPoP

DPoP (RFC 9449) binds tokens to a private key generated inside the client. At issuance the server records the key thumbprint in the cnf.jkt claim. Every subsequent request must include a fresh, signed proof JWT tied to the exact HTTP method and URL. A token stolen without its private key is rejected because the server demands a valid proof. The implementation includes stateless HMAC nonces, a jti replay cache per key, and an allow-list of asymmetric algorithms only. A separate package, redb.Identity.Resource.Dpop, lets resource APIs perform the same validation.

Layer Three: Rapid Revocation

Even strong binding requires fast revocation when a user departs, a device is lost, or an incident is confirmed. redb.Identity supports RFC 7009 token revocation, refresh-token rotation, idle-timeout sessions updated on real activity, and backchannel logout in both push and pull modes. The pull feed of revoked session identifiers allows any recovering replica to query “/revoked-sids/since?cursor=…” and catch up without missing events. BFF validation itself checks this list on every cookie request so that a global sign-out immediately terminates live sessions across all replicas.

Supporting Controls

Password history, TOTP step locking to prevent replay within the acceptance window, server-side hashed one-time codes for SMS and email, atomic recovery-code consumption, constant-time comparisons via CryptographicOperations.FixedTimeEquals, and three-tier rate limiting (IP, client_id token bucket, and IP-plus-user) are all implemented. Proxy headers are sanitized before reaching rate limiters or block counters, and idempotency caches sit after authorization checks.

Related articles

Securitylab•Other

Bitrix24 Introduces Cowork/Code AI Agent for Corporate Task Automation and App Building

Bitrix24 has launched Cowork/Code, an AI application that combines file management, company data access, and application development inside a controlled corporate environment. The tool features an AI agent capable of executing multi-step workflows such as locating records, comparing documents, generating tables, and saving results to shared folders. It operates in two modes: Cowork for one-time tasks like overdue task reports or client preparation, and Code for creating reusable tools such as dashboards or notification bots. A memory technology called Radiant stores context from chats, tasks, meetings, and employee data to deliver more accurate, personalized responses over time. The platform addresses common risks of vibe coding by keeping code, data access, and distribution within the Bitrix24 ecosystem hosted on Russian infrastructure. A free tier provides limited usage, with paid plans required for sustained team operation.

Habr•Other

Klark and Klara Launch Self-Hosted Corporate Messenger and Task Manager for On-Premise Data Control

Klark and Klara are two integrated products designed to keep corporate communication and task management entirely within company infrastructure. Klark functions as a Telegram-like messenger with personal chats, supergroups, channels, voice messages, file sharing, and video calls powered by LiveKit. Klara serves as a streamlined task and knowledge base system replacing complex setups like Jira and Confluence. Both run via Docker Compose on customer servers using PostgreSQL, Redis, FastAPI, and React, with built-in antivirus scanning via ClamAV. Key security measures include mandatory TOTP two-factor authentication, LDAP integration, content security policies, and automatic session invalidation on token reuse. The combination allows direct task creation from chat messages and displays tasks alongside conversations in a unified interface.

AntiMalware•Other

Russia's Taxi Market Overrun by Illegal Drivers Using Fake Accounts and Gray Intermediaries

Russian taxi aggregators are increasingly relying on complex chains of intermediaries that allow drivers without proper licenses, experience, or even Russian permits to operate. These gray schemes involve dispatch services, car fleets, individual entrepreneurs, and so-called podklyuchashki that sell ready-made accounts for 3-7 thousand rubles after minimal verification. A high-profile incident in Odintsovo exposed how a driver refusing service to a disabled veteran of the special military operation was later deported, revealing a corporate maze where the vehicle, the connecting IP, and the driver had no direct link to the aggregator. Official data shows over 900,000 vehicles registered in the FGIS Taxi system, yet more than 1.5 million drivers may be operating outside legal requirements. With Russians taking around 10 million taxi trips daily, the lack of accountability has contributed to over 3,100 accidents involving taxis in 2025, resulting in 143 deaths and more than 3,800 injuries. Courts remain inconsistent in assigning liability across aggregators, fleets, and individual drivers. Experts are calling for aggregators to be designated as carriers with mandatory checks and joint liability.

AntiMalware•Other

Russians Offered Unofficial 5G Activation on iPhone for 399 Rubles with No Guarantees

A Russian service called 5G First is selling a tool that removes Apple's 5G restrictions on iPhones for 399 rubles without requiring a jailbreak. The method works by modifying carrier profile settings that control which network features are permitted for a given SIM card. A free alternative named CarrierSIM achieves the same result by forcing the device to adopt the Vodafone Hungary carrier profile where 5G is already enabled. Both solutions are described as experimental, depend on specific iOS versions, operators and SIM cards, and offer no assurance they will survive future system updates. The Ministry of Digital Development is already in discussions with Apple about enabling 5G officially on Russian iPhones. Successful activation of the 5G menu option does not create network coverage where Russian operators have not yet deployed it.