Are they just closely protected by greybeards who won't listen to reason?
Question comes from a true place of ignorance/curiosity, I definitely understand the need to have unambiguous, easy to implement security tokens without the foot-guns.
Are they just closely protected by greybeards who won't listen to reason?
Question comes from a true place of ignorance/curiosity, I definitely understand the need to have unambiguous, easy to implement security tokens without the foot-guns.
If you're going to put in the work (which I am), you might as well start with a clean slate rather than trying to piecemeal security improvements into their design-by-committee spec.
Oh hey look, he standardised POSIX threads. maybe everything bad is from POSIX?
"Everything bad has something to do with javascript"? Don't put words in my mouth.
"A C# developer at Microsoft" plus a javascript explosion. Aren't you just confirming my point? Those new people didn't materialise out of thin air, they may have been software developers who had to change focus rapidly. And they didn't necessarily knew how their creations could be misused under the rules of that new javascript world.
And he doesn't look old enough to be a designer of POSIX threads.
(if you don't like my expression about the "vibe" then I'll give you an example of a protocol with a C vibe: the type value would be a fixed-length field with a table of integer IDs written in the standard; everyone would complain about integer sign, wrap-arounds and the new extension field that was added because we ran out of IDs)
Or even just an opinionated library with some basic guardrails to prevent bad configurations.
JWT is the opposite of that. It's essentially a reenactment of the bad parts of 90s crypto, including RSA and NONE ciphers.