"... with 32 bit keys."
The whole thing is editorialized to make it sound like the problem is with JWTs. It's not, this is just plain old improper use of perfectly good crypto.
Brute-forcing 32 bit HMAC keys isn't exactly newsworthy.
The whole thing is editorialized to make it sound like the problem is with JWTs. It's not, this is just plain old improper use of perfectly good crypto.
Brute-forcing 32 bit HMAC keys isn't exactly newsworthy.
Also the title "Brute forcing JWT in C" could not be clearer. This is not "0day found in JWT", or just "breaking JWT". This is brute force & nothing more
This is actually editorialized to make it sound the way it really is