HNHacker News
TopNewBestAskShowJobs

jmdc

20 karma · joined May 28, 2024

submissionscomments
jmdc··on Elegance is Bullshit
But is it actually an Orwell Quote? I am not trying to call you out - I am actually curious. Please share a source.
jmdc··on Elegance is Bullshit
Politics and the English Language is my favorite essay. I didn't recognize the quote, so I looked and couldn't find it in the text either.

https://www.orwellfoundation.com/the-orwell-foundation/orwel...

jmdc··on Should I use JWTs for authentication tokens?
I agree that DPoP - especially the nonce - is quite complex, but I don't think it's as bad as you make out.

Proof tokens can only be used for a narrow window of time (seconds to minutes), so you just need a cache of recently seen token identifiers (jtis) to do replay detection. And proof tokens are bound to an endpoint with the htm and htu claims. They can't be used across services, so I don't see a need for that replay cache to be shared across all services.

jmdc··on Should I use JWTs for authentication tokens?
DPoP is an OAuth extension that defends against token replay by sender constraining tokens. It is a new-ish spec, but support is pretty widespread already. It's used in a lot of European banking that has pretty strict security requirements, and it's supported by some of the big cloud identity providers as well as the OAuth framework I work on, IdentityServer. We have sample code and docs etc on our blog: https://blog.duendesoftware.com/posts/20230504_dpop/