logoalt Hacker News

er0k • today at 3:53 PM • 4 replies • view on HN

wow I am so surprised to hear once again how JWTs are terrible

https://www.howmanydayssinceajwtalgnonevuln.com/


Replies

fabian2k • today at 4:05 PM

Someone not verifying the signature at all is not a mistake where you can blame the JWT spec itself.

➕ show 2 replies
talon8635 • today at 4:38 PM

Does this extend to OIDC? I’m not knowledgeable on the topic but it uses JWT right? Is it also prone to poor implementation? If you just error on alg=none does that solve it?

Perz1val • today at 4:10 PM

Idk if that's not too much of an oversimplification, maybe more like JWTs are an indicator/enabler of architecture level bugs?

skhameneh • today at 4:21 PM

Other commenters are suggesting you can’t blame the spec for end implementation mistakes, except that’s one of the many issues - JWT being so error-prone is a problem.

I use JWT just for handling of tokens, because it’s so well supported, but I won’t use it for anything more than token storage _because_ it is so vulnerable to mistakes.

The fact that mistakes are so easy to make is indicative of poor design in the spec itself.