3 ms·
> * JWT can be secure if you are careful https://www.howmanydayssinceajwtalgnonevuln.com/ https://www.howmanydayssinceajwtalgnonevuln.com/ https://www.zofre
by CiPHPerCoder 5y ago
> * JWT can be secure if you are careful
https://www.howmanydayssinceajwtalgnonevuln.com/ https://www.howmanydayssinceajwtalgnonevuln.com/
https://www.zofrex.com/blog/2020/10/20/alg-none-jwt-nhs-contact-tracing-app/ https://www.zofrex.com/blog/2020/10/20/alg-none-jwt-nhs-cont...
https://twitter.com/SchmiegSophie/status/1413248896227155968 https://twitter.com/SchmiegSophie/status/1413248896227155968
https://twitter.com/tqbf/status/1414087907938377735 https://twitter.com/tqbf/status/1414087907938377735
etc.
> * there is wide support for JWT. (See for example this IETF draft https://datatracker.ietf.org/doc/html/draft-ietf-oauth-access-token-jwt-13 https://datatracker.ietf.org/doc/html/draft-ietf-oauth-acces... as well as the numerous libraries)
Yes, and my intention is to make sure there is wide support for PASETO in the near future too.
> Maybe paseto can eventually displace JWT, but I have a hard time seeing how that happens.
It won't ever 100% displace JWT in the same way that we won't ever 100% displace PHP 4 from the Internet, or the legions of badly written tutorials full of SQL Injection vulnerabilities that new programmers learn from.
The goal isn't to displace JWT, though. The goal is to provide a secure-by-default, easy-to-use, hard-to-misuse alternative.
After all, just because it's possible to implement a set of building blocks "securely" doesn't mean the kit is secure. I wrote more about this here: https://paragonie.com/blog/2019/10/against-agility-in-cryptography-protocols https://paragonie.com/blog/2019/10/against-agility-in-crypto...
But even if you don't care about all of that, the upcoming PASETO versions (v3/v4) offer cryptographic properties that JWT does not, such as exclusive ownership. https://github.com/paragonie/paseto/blob/master/docs/Rationale-V3-V4.md#v3-signatures-prove-exclusive-ownership-enhancement https://github.com/paragonie/paseto/blob/master/docs/Rationa...
------
Also, in case it wasn't obvious: PASERK is still a work-in-progress; things might change. Wait until you see a `1.0` tag before trying to implement it.
There is a reference implementation in PHP, but that's also experimental and no stable release has occurred there yet.
- mooreds 5y ago> Yes, and my intention is to make sure there is wide support for PASETO in the near future too. That would be great, thanks for your hard work. > The goal isn't to displace JWT, though. The goal is to provide a secure-by-default, easy-to-use, hard-to-misuse alternative. That makes sense, appreciate the insight.