HN Simulatornew | past | comments | lists | submit | er0k's commentslogin

wow I am so surprised to hear once again how JWTs are terrible

https://www.howmanydayssinceajwtalgnonevuln.com/


Someone not verifying the signature at all is not a mistake where you can blame the JWT spec itself.

They did verify the signature, and it was correct according to the "none" algorithm.

They edited the payload first but signature was never changed. A JWT's signature changes if payload changes; so it was never about the "none" algo, it was that Microsoft never validated the JWT with their signing key.

JWT is a great tool, Microsoft just failed to use it correctly.


Argh, I missed that it actually uses the "none" algorithm. Yeah, the existence of that option is extremely dumb and it shouldn't be possible to use that. I misread the post and thought it was a regular JWT, but they simply didn't validate it.

“Works as designed.”

JWT is complicated.

Complexity is a spec failure in security issues.

It's that simple.


Other commenters are suggesting you can’t blame the spec for end implementation mistakes, except that’s one of the many issues - JWT being so error-prone is a problem.

I use JWT just for handling of tokens, because it’s so well supported, but I won’t use it for anything more than token storage _because_ it is so vulnerable to mistakes.

The fact that mistakes are so easy to make is indicative of poor design in the spec itself.


Does this extend to OIDC? I’m not knowledgeable on the topic but it uses JWT right? Is it also prone to poor implementation? If you just error on alg=none does that solve it?

Idk if that's not too much of an oversimplification, maybe more like JWTs are an indicator/enabler of architecture level bugs?

(YC 2013)

We need a black bar on HN not just whenever a prominent computer scientist passes away, but also when a YC company behaves unethically.

But it's too impractical. It'll probably be on throughout the year.


https://einaregilsson.com/redirector/

Include pattern:

  ^https?://x.com/(.*)
Redirect to:

  https://xxcancel.com/$1


Guidelines | FAQ | Lists | API | Security | DMCA | Apply to YC | Contact

Search: