upvote
Someone not verifying the signature at all is not a mistake where you can blame the JWT spec itself.
reply
They did verify the signature, and it was correct according to the "none" algorithm.
reply
Argh, I missed that it actually uses the "none" algorithm. Yeah, the existence of that option is extremely dumb and it shouldn't be possible to use that. I misread the post and thought it was a regular JWT, but they simply didn't validate it.
reply
“Works as designed.”
reply
JWT is complicated.

Complexity is a spec failure in security issues.

It's that simple.

reply
Does this extend to OIDC? I’m not knowledgeable on the topic but it uses JWT right? Is it also prone to poor implementation? If you just error on alg=none does that solve it?
reply
Other commenters are suggesting you can’t blame the spec for end implementation mistakes, except that’s one of the many issues - JWT being so error-prone is a problem.

I use JWT just for handling of tokens, because it’s so well supported, but I won’t use it for anything more than token storage _because_ it is so vulnerable to mistakes.

The fact that mistakes are so easy to make is indicative of poor design in the spec itself.

reply
Idk if that's not too much of an oversimplification, maybe more like JWTs are an indicator/enabler of architecture level bugs?
reply