Hacker News new | ask | show | jobs
by tsarchitect 388 days ago
Dabvid Blevins has a great video (2018) that mentions JWTs https://www.youtube.com/watch?v=osQmFNm0YDU

He discusses the architectural advantages of JWT but also discusses JWTs lacking

"JWTs are a passport without a picture. A very dangerous thing".

His solution: OAuth2 + JWT + Signatures