3 ms·
Okay, so hack into a site that uses JWTs for login, if it’s so insecure we should be seeing loads of attacks against them right? Stolen tokens everywhere being
by andy_ppp 4mo ago
Okay, so hack into a site that uses JWTs for login, if it’s so insecure we should be seeing loads of attacks against them right? Stolen tokens everywhere being used to impersonate people and other things. For example I believe ChatGPT is using Auth0 which uses JWTs, so you can hack this insecure token system? Should be easy right given the extremity of the warning that JWT is the big problem here.
- mawadev 4mo agoFinally, feels like the blog stirs up unnecessary drama
- Maxion 4mo agoA lot of these type of coding practice debates are theoretical. IMO coding is more-or-less fancy blue collar work. What matters is what works in practice, not what works in theory.
- yencabulator 4mo agohttps://cybercx.co.nz/blog/json-web-token-validation-bypass-in-auth0-authentication-api/ https://cybercx.co.nz/blog/json-web-token-validation-bypass-...
- jcmartinezdev 4mo agoThis is really old. JWTs are very safe.
- yencabulator 4mo agoJWT is a bad spec leading to stupid mistakes all over the ecosystem. "Just be very careful in all of the implementations forever" is a horrible security stance.