Using JSON Web Tokens to Authenticate JavaScript Front-Ends on Rails
zacstewart.com
zacstewart.com
The main vulnerability I worry about when I see it being used is in the implementation by the end user or library, in that you must validate the algorithm used to sign the key [0]; but, many libraries assume that users will read the spec before plopping in a new auth scheme into their app, and don't do this by default.
Secondly, it's important to remember that JWTs can be decoded anywhere, but verified as signed by you.
I've been using JWT-go [1] in my most recent app, and it's been great.
[0]: https://auth0.com/blog/2015/03/31/critical-vulnerabilities-i...
I was going to point this out in my own post, but wanted to finish reading the article first. Of course if you go the signed route, you accept the payload is fully readable, and you must confirm the signature for every request.
When it's asymetrically signed, you are supposed to verify the signature.
Yes, if you are going to implement/support a number of mixed methods for generating tokens (or a use a client library that does), you absolutely need to confirm that the expected header/signature matches.
https://tools.ietf.org/html/draft-ietf-jose-json-web-encrypt...
99 times out of 100, the problems people try to solve around APIs with cryptography are better solved with simple 256-bit random integer tokens.
2) To avoid this sort of repeated question, do you have a set of guidelines to avoid common mistakes and generally Do The Right Thing for standard security problems?
[1] http://research.google.com/pubs/pub41892.html
[2] http://hackingdistributed.com/2014/05/16/macaroons-are-bette...
When it's demo-able I'll definitely post a Show HN. In the meantime, if you'd like more details I'd love talk one-on-one. Feel free to contact me via my email (at the bottom of OP), or @zacstewart anywhere else.