4 ms·
A good reminder to use long HMAC secrets or sign your JWT with RSA.
by davewritescode 10y ago
A good reminder to use long HMAC secrets or sign your JWT with RSA.
- brendanrius 10y agoDefinitely, you would be surprised by the amounts of JWT using very simple secrets
- porpoisemonkey 10y agoYeah - that's unfortunate. The spec clearly outlines a required minimum key length and it could be easily enforced in JWS libraries to make things more secure.
- spydum 10y agoI am curious why more folks don't use rsa keys anyways? Seems like that makes signature validation even easier (publish the location of the public key for validation). Then your endpoints don't need to exchange secrets at all?
- davewritescode 10y agoIt makes rotating the secret a hell of a lot easier as well.
- lvh 10y agoI'm not sure I follow. You still need to communicate the public key securely.
- deleted 10y ago[deleted]
- crgwbr 10y agoWe use RSA signed JWTs for quite a few services and it's been a joy so far. Makes key rotation without downtime super easy and (obviously) doesn't have any of the dangers associated with a shared secret. https://github.com/crgwbr/asymmetric_jwt_auth https://github.com/crgwbr/asymmetric_jwt_auth
- nrjdhsbsid 10y agoSigning jwt with RSA is a bad idea. Asymmetrical encryption methods are orders of magnitude slower than hmac. It sounds like a nice thing to do but it's really really slow compared to hmac. That's why TLS only uses the public key to exchange a symmetric key then switches over to AES or whatever.
- tscs37 10y agoJWT with RSA or Ed25519 is definitely not a bad idea there.
- lvh 10y agoJWT does not define Ed25519 as part of the spec. It is supported "off-label" in one JWT library I could find (Joken) for a relatively uncommon language (Elixir). Frustratingly, JWT defines a tons of stuff, where few are required but some are "Recommended" and some are "Recommended+". I'm not sure what "Recommended+" means, but apparently it means "has known cryptographic flaws", because RSA with PKCSv15 padding is "Recommended+".
- tscs37 10y agoI kinda went over the standard on that. The Go library I use allows to define custom algorithms, so I just set alg to ED2 and use it. It's within the app only so it doesn't hurt much. Also agree, it's rather frustrating that JWT is so well defined but something as simple as using Ed25519 is not part of the standard yet.
- buckhx 10y agoES256 is in the spec at least
- CiPHPerCoder 10y ago