logoalt Hacker News

milkshakestoday at 4:41 AM1 replyview on HN

well, you're in luck, they are JWTs in fact. JWTs in JWTs, so extra secure.


Replies

Freak_NLtoday at 7:35 AM

And of course, because the inner JWT is already signed, why bother signing the outer one? Just validate the inner one!

I'm feeling sorry for those poor abused JWTs in this vulnerability.