Argh, I missed that it actually uses the "none" algorithm. Yeah, the existence of that option is extremely dumb and it shouldn't be possible to use that. I misread the post and thought it was a regular JWT, but they simply didn't validate it.
They edited the payload first but signature was never changed. A JWT's signature changes if payload changes; so it was never about the "none" algo, it was that Microsoft never validated the JWT with their signing key.
JWT is a great tool, Microsoft just failed to use it correctly.
er0k · · focus · HN ↗
<a href="https://www.howmanydayssinceajwtalgnonevuln.com/" rel="nofollow">https://www.howmanydayssinceajwtalgnonevuln.com/
fabian2k · · focus · HN ↗
buckle8017 · · focus · HN ↗
Complexity is a spec failure in security issues.
It's that simple.
meindnoch · · focus · HN ↗
alex_suzuki · · focus · HN ↗
fabian2k · · focus · HN ↗
teamolHuang · · focus · HN ↗
JWT is a great tool, Microsoft just failed to use it correctly.