20 ms·
That is definitely strange, if it is not sensitive data, would you mind sharing the JWT and the original secret? or try to find another example where it behaves
by brendanrius 10y ago
That is definitely strange, if it is not sensitive data, would you mind sharing the JWT and the original secret? or try to find another example where it behaves like this?
Thanks
- jsd1982 10y agoIt is sensitive data so I can't share the payload for a (possibly unfounded) fear of brute-forcing the correct key used. I can tell you that the key is not an ASCII string (it is a random sequence of bits). The jwt.io debugger verified the signature when I gave it the proper key and failed to verify with the key "e" that this tool reported.