Hacker News new | ask | show | jobs
by edem 980 days ago
i have been telling teams for years that jwts are only good for one-off processes. they don't even bother to use jewes, sometimes there is no signature validation. no wonder broken authorization is the top 1 security problem