4 ms·
There’s so much FUD around JWT that I feel compelled to answer this everytime it comes up. Just to get it out of the way, you’re correct that the JWT spec does
by davewritescode 9y ago
There’s so much FUD around JWT that I feel compelled to answer this everytime it comes up.
Just to get it out of the way, you’re correct that the JWT spec doesn’t do a lot to prevent implementors from doing stupid things, particularly bad was downgrade attacks from asymmetric to symmetric keys.
Here’s the thing, these issues don’t exist anymore. Amazon’s Cognito relies heavily on JWT and I tend to trust Amazon’s security folks.
- jchw 9y agoThis is not FUD. It is a design flaw. It is now widely recognized that the header component of the JWT token cannot be used except to reject a token, making it pretty close to absolutely useless (except for debugging.) HOWEVER. Before this was recognized, most JWT implementations were broken and were easily susceptible to the most basic of downgrade attacks. Downgrading from asymmetric to symmetric was a slap in the face for obvious reasons, but that's just the last round of problems. The early problems were even more ridiculous; many libraries would readily downgrade to 'none' and turn off protection altogether. Not just Amazon Cognito, but Google's OIDC implementation, and indeed, all OIDC implementations, use JWT. JWT implementations today are hopefully no longer susceptible to basic lapses in security. But there's good reason for its reputation: the way it's designed lead to these trivial downgrade attacks. Having the token specify the algorithm was a bad decision, and it lead to bad implementations. Importantly, someone implementing JWT today could easily make some of the same mistakes if they aren't careful. I hope a future JWT release entirely removes the information from the token and just forces the client/server to agree statically.
- tptacek 9y agoI agree strongly that JWT is badly flawed, and that criticisms of JWT don't constitute "FUD". JWT's uptake has been alarming given how little cryptographic engineering input the format seems to have received, versus how complex it is under the hood. That said: Asymmetric crypto is a crypto code smell. You use it when you absolutely have to because there's no other way to express what you're trying to accomplish. It is much harder to get public key crypto right than it is to safely use a "Seal/Unseal" AEAD interface. One of the things that alarms me about JWT is that it's a format that presumes developers might want to effortlessly switch between symmetric and asymmetric crypto, as if they were just two different ways of solving the same underlying problem.
- lvh 9y ago"Amazon uses JWT" and "Amazon knows what they're doing" are not unreasonable statements, but it doesn't follow that "therefore JWT is now fine for everyone". You can make that argument for a lot of different footgun specs. I'm not saying JWT implies broken. I'm saying that JWT plus sub-billion-dollar-company-security-budget often leads to disaster. I'm also saying it's an unforced error, in that people do that in order to solve a problem they most likely don't have. It's clear that some people can do JWT correctly, just like e.g. some people can do OAuth2 correctly (to add another example to your list: Google/GSuite-as-an-IdP). That doesn't make it a safe and well-designed spec, and it doesn't make it great general advice.
- eddieroger 9y agoAmazon are the same folks who store their infra status page on their own infra, which is fine when it's up, and pretty useless when it's down. Even the smartest people are still just people - it's worth trusting several groups of smart people over just one.