3 ms·
> This is why Disney+ and Fortnite logins were hijacked in the first place Citation? I'm in total agreement with the problem of unexpiring tokens, but last I
by ergothus 7y ago
> This is why Disney+ and Fortnite logins were hijacked in the first place
Citation? I'm in total agreement with the problem of unexpiring tokens, but last I heard the suspected culprit in Disney+ was credential re-use. If there's newer info, I'd love to get a pointer to it.
> For that reason, Just do not use JWTs.
That seems a bit sweeping. You can apply the "unencrypted by default" dilemma to just about everything. Noting that you have to take an extra step doesn't invalidate the entire concept.