public marks

PUBLIC MARKS from Spone with tags security & jwt

08 May 2017 10:45

Things to Use Instead of JWT | Kevin Burke

You might have heard that you shouldn't be using JWT. That advice is correct - you really shouldn't use it. In general, specifications that allow the attacker to choose the algorithm for negotiation have more problems than ones that don't (see TLS). N libraries need to implement M different encryption and decryption algorithms, and an attacker only needs to find a vulnerability in one of them, or a vulnerability in their combination. JWT has seen both of these errors; unlike TLS, it hasn't already been deployed onto billions of devices around the world.

Spone's TAGS related to tag security

api +   application +   astuces +   authentication +   bcrypt +   best practices +   cryptage +   crypto +   développement +   firewall +   flickr +   framework +   guidelines +   hacks +   hashing +   html +   identity +   javascript +   jQuery +   jwt +   linux +   mot de passe +   mp3 +   openid +   opensource +   organisation +   passwords +   php +   plugin +   protocol +   proxy +   rails +   rest +   salt +   software +   spam +   spyware +   trust +   upload +   ux +   xml +