4 ms·
> I can't find the specification/rfc of Paseto. https://github.com/paragonie/paseto/tree/master/docs https://github.com/paragonie/paseto/tree/master/docs http
by CiPHPerCoder 7y ago
> I can't find the specification/rfc of Paseto.
https://github.com/paragonie/paseto/tree/master/docs https://github.com/paragonie/paseto/tree/master/docs
https://paseto.io/rfc/ https://paseto.io/rfc/
> It looks more of a php lib.
https://paseto.io/ https://paseto.io/ -- Several languages implement PASETO.
> To me it seems the author is not familiar with JWT[0]
How does one demonstrate familiarity with JWT beyond analyzing/critiquing the RFCs for JWT and correlating the specific language of the standard with real-world vulnerabilities of JWT implementations?
> and tries to solve the wrong problems(e.g assumes the idp or library being used are compromised.)
Assuming something that has happened several times already isn't a "wrong problem". https://auth0.com/blog/critical-vulnerabilities-in-json-web-token-libraries/ https://auth0.com/blog/critical-vulnerabilities-in-json-web-...