3 ms·
> Comes from a PHP consulting firm, promoting their own alternative proposal (which hardly anyone else seems to discuss or use). So I think #1 above is really a
by CiPHPerCoder 8y ago
> Comes from a PHP consulting firm, promoting their own alternative proposal (which hardly anyone else seems to discuss or use). So I think #1 above is really about drawing eyeballs and selling services, more so than providing clear information for a newcomer to follow.
There was a recent (November 2018) talk at London Gophers about JWT Alternatives (slides here: https://speakerdeck.com/hako/exploring-alternatives-to-json-web-tokens-jwt https://speakerdeck.com/hako/exploring-alternatives-to-json-...).
Keep in mind that PASETO didn't exist until the middle of 2018, so the main reason "hardly anyone else" seems to use it is precisely because it takes time for standards to be adopted.
If you take a look at https://paseto.io https://paseto.io, you'll see that there are implementations of PASETO (our proposed alternative) in multiple programming languages by other companies and individuals. All of these implementations are open source and under very permissive licenses (MIT or ISC).
Additionally, a great deal of time and effort went into the PASETO documentation, so that developers can understand not only how to implement it themselves, but also why it was designed the way it is. https://github.com/paragonie/paseto/tree/master/docs https://github.com/paragonie/paseto/tree/master/docs
Given all of the above, is it really fair to write PASETO off as an attempt to sell services?
Claiming that the original article is meant to sell services doesn't make sense either: If developers keep using unsafe tools, they will continue to be less secure and I'll have an easier time selling "make your products/services more secure" services to developers. The best thing to do, to meet such an incentive, is to say nothing publicly and let the easy money keep rolling in.
So one of two things is happening:
1. You don't correctly understand our intentions.
2. We're really bad at understanding our own incentives, and it's a miracle we've been in business for 4 years.
- hoffs 8y agoI mean, your homepage is pretty damn lacking and you even put something like this without putting any sources 'This has led to many security experts declaring boldly, "Don't use JWT!"'. This just looks like a poor attempt at making something 'better'.
- CiPHPerCoder 8y ago> I mean, your homepage is pretty damn lacking Do you honestly believe cybersecurity decisions should come down to how snazzy a homepage is, rather than a company's reputation? > and you even put something like this without putting any sources That article being discussed in this thread in particular quotes: 1. The opinions of other security experts 2. RFC 7515, section 4.1.1 3. The auth0 article about RS256/HS256 confusion 4. RFC 7518 5. The Adobe attack on ECDH-ES What additional kind of sources do you need? The arguments should be sufficiently supported by the material available. > This just looks like a poor attempt at making something 'better'. By what metrics could we make this attempt less "poor"? What specific changes do you need to see?