logoalt Hacker News

kyrrayesterday at 6:44 PM1 replyview on HN

JWT used to be bad due to libraries with poor defaults. Downgrade attacks were fairly common a number of years ago.

Since most of the common libraries across all languages have gotten more sane defaults, it actually is pretty secure nowadays.


Replies

tptacekyesterday at 8:03 PM

If we stipulate that, we're still left wondering what the utility is of a standard that creates affordances for the insecure defaults, as opposed to just designing it right from the beginning.

show 2 replies