3 ms·
Isn't this the point of JWTs that are signed with a shared secret (or public-private) but contain the right / necessary scopes?
by maxboone 3y ago
Isn't this the point of JWTs that are signed with a shared secret (or public-private) but contain the right / necessary scopes?
- cjonas 3y agoPretty sure this is based on one of those "login with Facebook" oAuth apps where your just using Facebook as the IDP. They were probably using the token to lookup the email address (via 'profile' scope) but not validating that the token originated from their connected app. Also, this is why the "client secret" needs to be kept secret (so a hacker can't trick users to login via your connected app)
- apsurd 3y agothe jwt isnt tampered with. imgur servers did not validate the decoded payload matched their fb app id. it says in the docs be sure too match on the app id because fb isn't going through the ceremony of checking that your oAuth key is registered to a specific app id and therefore only valid together. app id is considered arbitrary payload metadata in this sense.
- tiarafawn 3y agoThis problem/attack is called "confused deputy". It's surprisingly hard to find a link that correctly explains the problem and its mitigations. This one is correct but not very verbose: https://medium.com/@fhbro/confused-deputy-c9e75eb7df00#8edf https://medium.com/@fhbro/confused-deputy-c9e75eb7df00#8edf