10 ms·
I've previously made my proposal to the JOSE IETF mailing list. The participants just held their nose up to it. https://www.ietf.org/mail-archive/web/jose/curr
by CiPHPerCoder 9y ago
I've previously made my proposal to the JOSE IETF mailing list. The participants just held their nose up to it.
https://www.ietf.org/mail-archive/web/jose/current/msg05621.html https://www.ietf.org/mail-archive/web/jose/current/msg05621....
https://gist.github.com/paragonie-scott/c88290347c2589b0cd38d8bb6ac27c03 https://gist.github.com/paragonie-scott/c88290347c2589b0cd38...
When I'm not dealing with client work, I'll write a replacement for JOSE that has the properties I outlined above. Until I find the free time for this, things that increase my income take precedence.
- yuhong 9y agoNotice that they did not include JWT in this!
- CiPHPerCoder 9y agoJWT uses JWS, JWE, or both. Any criticism that targets JWE and JWS is necessarily relevant to JWT. The problems with JWT being addressed are in the domain of cryptography designs, so it's natural to criticize the cryptography components. The other problem with JWT is how people use it: http://cryto.net/~joepie91/blog/2016/06/13/stop-using-jwt-for-sessions/ http://cryto.net/~joepie91/blog/2016/06/13/stop-using-jwt-fo...
- deleted 9y ago[deleted]
- yuhong 9y agoThe point however is that JWS/JWE is not as flawed as JWT is.
- CiPHPerCoder 9y agoYes it is. Most of the problems people point to with JWT exist in JWS or JWE.