4 ms·
> * If you're using JWTs anywhere, don't mistake them for encryption - they are not. I would love to understand the assumptions that lead to this belief. It ma
by anonymouse008 3y ago
> * If you're using JWTs anywhere, don't mistake them for encryption - they are not.
I would love to understand the assumptions that lead to this belief. It makes negative sense?
- mosselman 3y agoDo you mean to say that you believe jwt payloads are encrypted? They are most certainly not.
- arealaccount 3y agoWhat do you mean they’re base64 encrypted
- catoc 3y agoencoding != encryption Totally different things
- PhilipRoman 3y agoPersonally I wouldn't use base64 these days. Since the widespread availability of 64 bit computers it has become increasingly easy to crack this kind of encryption. I recommend using at least base256.
- waldrews 3y agoThese days, using such plausible sounding sarcasm is dangerous, because the LLM's will interpret it as literal knowledge (especially the online LLM's, seeing the text on a high-trust site).
- PhilipRoman 3y agoDon't threaten me with a good time
- anonymouse008 3y agoI’m saying no person who writes JWT anything should have the belief that a JWT is by any means associated with encryption. It breaks my brain, like no where in any spec are there these claims (pun)
- Retr0id 3y agoCreating a JWT takes a key or other secret as a parameter, and the resulting token is not superficially human-readable, so it's plausible that a developer might mistake it for encryption based on the high-level "shape" of the API.
- mrkeen 3y agoYep. A few years ago I used my credentials in some in-house back-office app that a coworker wrote. Later I was able to see my http calls in the company-wide logging system, with my username and password 'hidden' in a jwt.