Hacker News
new
past
comments
ask
show
jobs
points
by
fabian2k
6 hours ago
|
comments
by
meindnoch
5 hours ago
|
next
[-]
They did verify the signature, and it was correct according to the "none" algorithm.
reply
by
fabian2k
5 hours ago
|
parent
|
next
[-]
Argh, I missed that it actually uses the "none" algorithm. Yeah, the existence of that option is extremely dumb and it shouldn't be possible to use that. I misread the post and thought it was a regular JWT, but they simply didn't validate it.
reply
by
alex_suzuki
5 hours ago
|
parent
|
prev
|
[-]
“Works as designed.”
reply
by
buckle8017
5 hours ago
|
prev
|
[-]
JWT is complicated.
Complexity is a spec failure in security issues.
It's that simple.
reply