5 ms·
Counterpoint: https://paragonie.com/blog/2017/03/jwt-json-web-tokens-is-bad-standard-that-everyone-should-avoid https://paragonie.com/blog/2017/03/jwt-json-web
by CiPHPerCoder 7y ago
Counterpoint:
https://paragonie.com/blog/2017/03/jwt-json-web-tokens-is-bad-standard-that-everyone-should-avoid https://paragonie.com/blog/2017/03/jwt-json-web-tokens-is-ba...
- cryptica 7y agoThat article doesn't contain a single logical argument. >> JSON Web Tokens are Often Misused So is everything else. Name one programming concept which isn't often misused. >> There were two ways to attack a standards-compliant JWS library to achieve trivial token forgery The keyword here is "were" - Just like how people in Europe "were" dying from the Bubonic plague - It doesn't mean that Europe is unsafe today. The up-to-date reality is that JWT today has been battle-tested to an extent that few other web standards have. In a way, all the negative attention due to past issues has made it stronger. >> JSON Web Encryption is a Foot-Gun... this is somewhat like pointing a gun with 5 out of 6 loaded chambers directly at your foot ...And using session IDs inside a cookie is like eating a cookie laced with cyanide.
- enumjorge 7y agoCan you elaborate why session IDs inside cookies is dangerous?
- Supermancho 7y agoI can manipulate my cookies. I can forge my servserside session id for session hijacking. This is what I understood.
- CiPHPerCoder 7y ago> I can forge my servserside session id for session hijacking. This is what I understood. Forge this. For each session: session_id = bin2hex(random_bytes(32)) Yes, you can change what you send to the server. But you can't hijack another user's session in this probability space (2^-256) by blind guessing. Instead, you need another way to leak their credentials to hijack the session.
- cryptica 7y agoI didn't think so detailed but yes. My point was more that if you look at any technology concept, you will find vulnerabilities if it is misused.
- skrebbel 7y agoI'm impressed that you put your money where your mouth is and built & marketed an alternative: https://paseto.io/ https://paseto.io/ Anyone here got experience using Paseto in anger? (besides CiPHPerCoder who made it) I would love a JWT-like thing that's equally common yet better designed. But especially when using it in public APIs and the likes, acceptance has to be pretty broad. Anyone got insights as to how mainstream Paseto is getting?
- CiPHPerCoder 7y ago> Anyone got insights as to how mainstream Paseto is getting? Okta's a pretty big name in authn/authz and their engineers recently published an open source PASETO implementation. https://developer.okta.com/blog/2019/10/17/a-thorough-introduction-to-paseto https://developer.okta.com/blog/2019/10/17/a-thorough-introd... https://github.com/paseto-toolkit/jpaseto https://github.com/paseto-toolkit/jpaseto
- jillesvangurp 7y agoJudging from the number of stars of the various git repositories for different languages, there are a few people using it but not a whole lot. The most popular implementation seems to be php based. That suggest to me it's still early days for this. E.g. the Java implementation only has 13 stars, which is not a lot. Also it has a native dependency, which is not ideal. E.g. JWT has a pure Java implementation from oauth0. JWT has been out there for a few years and there are many uses of it that are fine. I've used it in the past and it was easy set up and get started with. The main criticism seems to be that users have too much wiggle room to do silly things like using alg=noneor that certain widely used algorithm combinations have some weaknesses. I guess that's valid but not a huge concern if you know what you are doing. Paseto looks like it improves by narrowing down the choices to some sane choices, which is a valid approach. Of course IETF could update the relevant RFCs to use the same algorithms for JWT at some point.
- anonsivalley652 7y agoPopularity != value. Get over false signals.
- rvz 7y agoFernet [0] was just as close to being a suitable and secure JWT replacement. But the specification wasn't really updated in a while so a simpler and another secure alternative to JWT and Fernet would be Branca [1] tokens that uses the same cryptography as PASETO v2.local [2]. Here's some trivia, the name comes from an italian drink from the 19th century named Fernet-Branca [3]. [0] - https://github.com/fernet/spec/blob/master/Spec.md https://github.com/fernet/spec/blob/master/Spec.md [1] - https://branca.io https://branca.io [2] - https://github.com/paragonie/paseto/tree/master/docs/01-Protocol-Versions#version-2-recommended https://github.com/paragonie/paseto/tree/master/docs/01-Prot... [3] - https://en.wikipedia.org/wiki/Fernet-Branca https://en.wikipedia.org/wiki/Fernet-Branca
- twic 7y agoFrom the 19th century perhaps, but used in some classic cocktails, and so still found in many bars: https://www.diffordsguide.com/cocktails/recipe/930/hanky-panky-cocktail https://www.diffordsguide.com/cocktails/recipe/930/hanky-pan...
- strbean 7y agoI've heard Fernet and Coke is the traditional "bartender's cocktail". Had a sip of my fiancee's once, it tastes like someone mixed every soda from the soda fountain with every herb and spice in their spice rack, and then squeezed a healthy dollop of toothpaste in for good measure.