3 ms·
Can't a system be DDoS'ed with wrongly signed JWTs as well? Is signature checking (much) cheaper than finding an opaque session ID in a database?
by hasley 4mo ago
Can't a system be DDoS'ed with wrongly signed JWTs as well?
Is signature checking (much) cheaper than finding an opaque session ID in a database?
- jongjong 4mo agoYes but it only impacts your stateless app servers which are easier to scale. Your backend services/stores are protected and not affected by the attack.