HNHacker News
TopNewBestAskShowJobs

brendanrius

90 karma · joined January 21, 2017

submissionscomments
brendanrius··on Jupyter C Kernel
You are right, naming branches this way is not really important and I will probably remove that part. I do not want to add friction to people who want to contribute since I know how painful it is to contribute on certain projects.
brendanrius··on Jupyter C Kernel
It does not yet :)
brendanrius··on Brute forcing JSON Web Tokens in C
From the readme: "If you are very lucky or have a huge computing power"

Also the title "Brute forcing JWT in C" could not be clearer. This is not "0day found in JWT", or just "breaking JWT". This is brute force & nothing more

This is actually editorialized to make it sound the way it really is

brendanrius··on Brute forcing JSON Web Tokens in C
That is definitely strange, if it is not sensitive data, would you mind sharing the JWT and the original secret? or try to find another example where it behaves like this?

Thanks

brendanrius··on Brute forcing JSON Web Tokens in C
Nice work, thanks for sharing
brendanrius··on Brute forcing JSON Web Tokens in C
If it is not sensitive information, I would be curious to know the JWT you tested with, the key used, and the key that program found
brendanrius··on Brute forcing JSON Web Tokens in C
I generated this one with jwt.io, but after testing it looks like pyjwt (which is a very common library) does exactly the same thing
brendanrius··on Brute forcing JSON Web Tokens in C
Depends on the secret
brendanrius··on Brute forcing JSON Web Tokens in C
It's clearer, I fixed it :)
brendanrius··on Brute forcing JSON Web Tokens in C
If only people respected RFCs
brendanrius··on Brute forcing JSON Web Tokens in C
Definitely, you would be surprised by the amounts of JWT using very simple secrets