5 ms·
Why a new standard than to push for reform to the current standard? Are they just closely protected by greybeards who won't listen to reason? Question comes f
by different_sort 6y ago
Why a new standard than to push for reform to the current standard?
Are they just closely protected by greybeards who won't listen to reason?
Question comes from a true place of ignorance/curiosity, I definitely understand the need to have unambiguous, easy to implement security tokens without the foot-guns.
- CiPHPerCoder 6y agoSimple answer: Because secure cryptography is backwards-incompatible with insecure cryptography, and the JOSE standards have a lot of legacy cruft that will be hard to jettison. If you're going to put in the work (which I am), you might as well start with a clean slate rather than trying to piecemeal security improvements into their design-by-committee spec.
- different_sort 6y agoThank you for your reply!
- pillfill 6y ago> Why a new standard than to push for reform to the current standard? Or even just an opinionated library with some basic guardrails to prevent bad configurations.
- kelnos 6y agoThat's tempting, but as long as a standard has design flaws, there will be libraries out there that don't prevent bad configurations, and people (through innocent ignorance) will use them and end up in a bad place.
- blattimwind 6y agoThe whole point of modern cryptography is to take all the oodles of rope to hang yourself with and hand it over to the cryptographers, to leave just the absolute minimum amount of rope with the application developers. JWT is the opposite of that. It's essentially a reenactment of the bad parts of 90s crypto, including RSA and NONE ciphers.
- joepie91_ 6y agoI mean, "basic guardrails" is basically exactly what Auth0 tried to do here with their algorithm check, and see how that turned out.
- inopinatus 6y agoSpeaking as a recidivist greybeard, not sure why you'd think we'd have anything to do with something as callow and unproven as Javascript.
- ZenPsycho 6y agoJWT has nothing to do with javascript, other than being one of the many many languages that have JWT implementations.
- de_watcher 6y agoIt has a huge vibe of incompetent reinwheeling that is natural to the javascript ecosystem because of the web explosion that gave us a large amount of people with no clue.
- ZenPsycho 6y agoJust because you have a poisoned view of javascript doesn't mean that everything bad has something to do with javascript. In this case JWT was designed by a C# developer at Microsoft. Maybe you can shift gears to whining about .NET in every thread now? Oh hey look, he standardised POSIX threads. maybe everything bad is from POSIX? https://www.microsoft.com/en-us/research/people/mbj/ https://www.microsoft.com/en-us/research/people/mbj/
- de_watcher 6y ago"You have a poisoned view"? That's just your opinion. I tried to base mine on a somewhat objective observation about speeds and volumes of stuff happening. "Everything bad has something to do with javascript"? Don't put words in my mouth. "A C# developer at Microsoft" plus a javascript explosion. Aren't you just confirming my point? Those new people didn't materialise out of thin air, they may have been software developers who had to change focus rapidly. And they didn't necessarily knew how their creations could be misused under the rules of that new javascript world. And he doesn't look old enough to be a designer of POSIX threads. (if you don't like my expression about the "vibe" then I'll give you an example of a protocol with a C vibe: the type value would be a fixed-length field with a table of integer IDs written in the standard; everyone would complain about integer sign, wrap-arounds and the new extension field that was added because we ran out of IDs)