3 ms·
Nice. Side note. The problem with JWTs is bigger than this. I "steal" web tokens all the time to get access to stuff outside the context the tokens were handed
by AtNightWeCode 3y ago
Nice.
Side note. The problem with JWTs is bigger than this. I "steal" web tokens all the time to get access to stuff outside the context the tokens were handed out in. If someone comes up with something really clever in this area there is money to be made.
- erhaetherth 3y agoWhat do you mean "outside the context the tokens were handed out in"? And isn't this the same as stealing a cookie or something?
- AtNightWeCode 3y agoIt is the same problem. My main issue with how it works is that typically tokens (and cookies) are valid until they expires. You browse some service and then it can be used by anybody for hours after that. And the methods for securing JWTs are either more tokens with shorter expiration time, using sessions or token black lists. Which kinda kills the beauty about having signed tokens.