logoalt Hacker News

fabian2k • today at 4:05 PM • 2 replies • view on HN

Someone not verifying the signature at all is not a mistake where you can blame the JWT spec itself.


Replies

meindnoch • today at 4:49 PM

They did verify the signature, and it was correct according to the "none" algorithm.

➕ show 2 replies
buckle8017 • today at 4:25 PM

JWT is complicated.

Complexity is a spec failure in security issues.

It's that simple.