logoalt Hacker News

Nursietoday at 4:48 AM0 repliesview on HN

They are!

But the systems that have been built around them are bad. Firstly in issuing these ‘root’ tokens at all, and secondly in not checking the claims properly.

A JWT is only as good as the systems it’s used by.