4 ms·
Not leaking tokens/token structure !== security through obscurity. I have seen idiotic implementations of JWT which effectively leak session details that shoul
by folkhack 6y ago
Not leaking tokens/token structure !== security through obscurity.
I have seen idiotic implementations of JWT which effectively leak session details that should only be kept server-side because "it was just easy to validate it on the client-end of things"... this specific example is an extreme one from my career history, and was caught long before it ever made it to prod.
But.
In this engineer's "hello world"-level implementation of JWT they effectively overloaded the session with incredibly sensitive data that should have been server-side-only (later to back-pedal and say this was a "dev only" implementation!). They did use JWT.io to debug their "implementation", and having done that did leak non-trivial details to a third party about how our authentication system was built.
This guy was a "junior engineer" who was hired because of nepotism - making this an even more extreme case... but really it's not. I've worked with incredibly ignorant, careless, not trustworthy, desperate, etc. people through my entire career (admittedly being those things myself sometimes).
Anywho - not leaking implementation details, and potential software/infrastructure secrets is not security through obscurity.