30 ms·
JWTs are the poster child of fragile signature design. If something is like JWTs, you should reconsider. Many implementations allowed JWTs with a null signature
by lambda 3y ago
JWTs are the poster child of fragile signature design. If something is like JWTs, you should reconsider. Many implementations allowed JWTs with a null signature scheme, completely bypassing any security!
- tzs 3y agoThe assertion was that allowing signatures for sub-parts of the information is extremely fragile. Your example of null signatures being allowed would equally affect sub-part signing and whole document signing, so doesn't really show that sub-part signing is a problem.
- ljm 3y agoIt’s also difficult to actually get people on board with the idea of supplying a user-specific signing key instead of relying on a global one. Instead they’ll end up persisted in a data store, making them stateful, because there’s no reliable way to invalidate such a token simply by rotating the signing key. Or using a cookie-backed session.