They edited the payload first but signature was never changed. A JWT's signature changes if payload changes; so it was never about the "none" algo, it was that Microsoft never validated the JWT with their signing key.
JWT is a great tool, Microsoft just failed to use it correctly.
er0k · · focus · HN ↗
<a href="https://www.howmanydayssinceajwtalgnonevuln.com/" rel="nofollow">https://www.howmanydayssinceajwtalgnonevuln.com/
fabian2k · · focus · HN ↗
meindnoch · · focus · HN ↗
teamolHuang · · focus · HN ↗
JWT is a great tool, Microsoft just failed to use it correctly.