Sitting with it for a while now and: what problem does DPoP actually solve? It doesn't protect against token theft from the local machine because you could just steal the keys instead. Is token theft via other means actually a real thing? I feel like if you've compromised a TLS-terminating front end proxy then grabbing tokens is not the most interesting thing you can do there.

0

If you have a fediverse account, you can quote this note from your own instance. Search https://nondeterministic.computer/users/mjg59/statuses/116068198231408921 on your instance and quote it. (Note that quoting is not supported in Mastodon.)