‹ BackHN Continuity

Thread

I could've accessed 17T Microsoft records

322 points · 128 comments · luispa

  1. er0k · · focus · HN ↗
    wow I am so surprised to hear once again how JWTs are terrible

    <a href="https:&#x2F;&#x2F;www.howmanydayssinceajwtalgnonevuln.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.howmanydayssinceajwtalgnonevuln.com&#x2F;

    1. fabian2k · · focus · HN ↗
      Someone not verifying the signature at all is not a mistake where you can blame the JWT spec itself.
      1. buckle8017 · · focus · HN ↗
        JWT is complicated.

        Complexity is a spec failure in security issues.

        It&#x27;s that simple.

      2. meindnoch · · focus · HN ↗
        They did verify the signature, and it was correct according to the &quot;none&quot; algorithm.
        1. alex_suzuki · · focus · HN ↗
          “Works as designed.”
        2. fabian2k · · focus · HN ↗
          Argh, I missed that it actually uses the &quot;none&quot; algorithm. Yeah, the existence of that option is extremely dumb and it shouldn&#x27;t be possible to use that. I misread the post and thought it was a regular JWT, but they simply didn&#x27;t validate it.
        3. teamolHuang · · focus · HN ↗
          They edited the payload first but signature was never changed. A JWT&#x27;s signature changes if payload changes; so it was never about the &quot;none&quot; algo, it was that Microsoft never validated the JWT with their signing key.

          JWT is a great tool, Microsoft just failed to use it correctly.

    2. Perz1val · · focus · HN ↗
      Idk if that&#x27;s not too much of an oversimplification, maybe more like JWTs are an indicator&#x2F;enabler of architecture level bugs?
    3. skhameneh · · focus · HN ↗
      Other commenters are suggesting you can’t blame the spec for end implementation mistakes, except that’s one of the many issues - JWT being so error-prone is a problem.

      I use JWT just for handling of tokens, because it’s so well supported, but I won’t use it for anything more than token storage _because_ it is so vulnerable to mistakes.

      The fact that mistakes are so easy to make is indicative of poor design in the spec itself.

    4. talon8635 · · focus · HN ↗
      Does this extend to OIDC? I’m not knowledgeable on the topic but it uses JWT right? Is it also prone to poor implementation? If you just error on alg=none does that solve it?
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.