logoalt Hacker News

magicalhippoyesterday at 10:30 PM2 repliesview on HN

For those of us not in the loop, COSE[1] is CBOR Object Signing and Encryption, with CBOR being a binary JSON alternative. It is patterned off JOSE, the JSON standards which includes favorites like JWK.

[1]: https://www.rfc-editor.org/info/rfc9052/


Replies

fortytoday at 6:46 AM

Moving to something else that JSON for this kind of thing is reasonable given the issues with parsing JSON which can cause 2 implementation to interpret it in 2 different ways.

https://seriot.ch/security/parsing_json.html

show 2 replies
mgaunardyesterday at 11:45 PM

so some sort of JWT alternative?

show 1 reply