Hacker News new | ask | show | jobs
by hparadiz 1 hour ago
Not checking the signature on every single JWT is the same as storing a password in plain text.