3 ms·
> This article is propaganda. Someone else called it FUD, now you're calling it propaganda. I'm seeing a pattern. > This is not the first article of it's kind
by CiPHPerCoder 8y ago
> This article is propaganda.
Someone else called it FUD, now you're calling it propaganda. I'm seeing a pattern.
> This is not the first article of it's kind; they just keep popping up over and over on HN with the same poor arguments. I usually post long explanations as to why these points are invalid but I'm tired of arguing with these people.
...they said, commenting on an Internet board where discussions (a.k.a. arguments) often unfold with these people.
Why are these arguments poor? In what sense does "JWT instead of server-side storage" make a better engineering decision?
> The real reason for these articles I think is that some developers had a very traumatic experience with poorly implemented JWT authentication system once in their life and now nothing will convince them otherwise.
Your ad hominem straw man argument notwithstanding, there are two orthogonal arguments that JWT defenders seem to conflate:
1. Don't misuse JWT in places it wasn't designed for. <- You are here
2. JWT is an error-prone cryptographic design and should be replaced with a better standard.
You can agree with one without agreeing with the other.
> Maybe JWTs don't make as. much sense for HTTP but for WebSockets they are absolitely crucial.
Would PASETO be a better fit than JWT for your envisioned WebSockets use case?
https://github.com/paragonie/paseto/tree/master/docs https://github.com/paragonie/paseto/tree/master/docs
- patterned867 8y ago> Someone else called it FUD, now you're calling it propaganda. I'm seeing a pattern. Maybe you should talk to someone about the patterns you are seeing. Maybe you can connect more unrelated things together to paint a mental portrait of others. Thanks for being inclusive.