Someone not verifying the signature at all is not a mistake where you can blame the JWT spec itself.
They did verify the signature, and it was correct according to the "none" algorithm.
JWT is complicated.
Complexity is a spec failure in security issues.
It's that simple.
They did verify the signature, and it was correct according to the "none" algorithm.