|
|
|
|
|
by lvh
2934 days ago
|
|
FWIW, this matches my experience. Large new enterprise systems have JWT all over the place. My first pass counterargument to this is: great! You also have FAANG’s security budget and know how to find and resolve bugs like the FB OAuth2.0 tokens being replayable from 1 relying party to another, right? No? Oh. The general subtext being: that’s nice but you know nothing of their rationale, underlying work that went into securing it, etc; so if you’re picking up a token metaformat without the massive work behind it, you’re just cargo culting. |
|