3 ms·
Oh hey, it's another "JWT libraries used to be terrible" article. Idiots shouldn't write authentication code. Especially when credentials are involved. Funny
by gant 9y ago
Oh hey, it's another "JWT libraries used to be terrible" article.
Idiots shouldn't write authentication code. Especially when credentials are involved.
Funny jwt-go was used as an example; it was never vulnerable to the alg-none attack:
https://github.com/dgrijalva/jwt-go/commit/2b0327edf60cd8e04d7ee6670b165c9580a42392 https://github.com/dgrijalva/jwt-go/commit/2b0327edf60cd8e04...
- kevinburke 9y agoI cover this point in the article
- developer2 9y ago>> it's another "JWT libraries used to be terrible" article Dead on. Sure, some early JWT implementations were poor... during the first few months that JWT was gaining traction. That was over 2 years ago. You may as well write an article about how Internet Explorer is awful, while referring to qualities present in IE 6. Disclaimer: I still dislike IE/Edge, but no longer have pertinent reasons as to why I maintain that opinion. There is not a single valid criticism of JWT from a security perspective. The only criticism outside of security considerations I'd view as valid is that the length of the strings quickly becomes bloated for the amount of information contained within (ie: inefficient bandwidth and storage usage, the same complaint as with long cookie headers requiring more TCP packets).
- kevinburke 9y agoUsability and implementation errors are security errors http://blogs.adobe.com/security/2017/03/critical-vulnerability-uncovered-in-json-encryption.html http://blogs.adobe.com/security/2017/03/critical-vulnerabili... see the "X.509" section here https://www.npmjs.com/package/jsonwebtoken https://www.npmjs.com/package/jsonwebtoken https://twitter.com/bcrypt/status/583070541336195072 https://twitter.com/bcrypt/status/583070541336195072