‹ BackHN Continuity

Thread

I could've accessed 17T Microsoft records

322 points · 128 comments · luispa

  1. er0k · · focus · HN ↗
    wow I am so surprised to hear once again how JWTs are terrible

    <a href="https:&#x2F;&#x2F;www.howmanydayssinceajwtalgnonevuln.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.howmanydayssinceajwtalgnonevuln.com&#x2F;

    1. skhameneh · · focus · HN ↗
      Other commenters are suggesting you can’t blame the spec for end implementation mistakes, except that’s one of the many issues - JWT being so error-prone is a problem.

      I use JWT just for handling of tokens, because it’s so well supported, but I won’t use it for anything more than token storage _because_ it is so vulnerable to mistakes.

      The fact that mistakes are so easy to make is indicative of poor design in the spec itself.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.