JWT

Oct
04
Why PASETO Might Not Be the JWT Replacement We Hoped For

Why PASETO Might Not Be the JWT Replacement We Hoped For

PASETO, a potential alternative to JWT, has sparked conversations within the security and developer community alike (for once). While PASETO
3 min read
Apr
06

JWT: A Cryptographic Love Story with Security, Vulnerabilities, and a State of Confusion

Folks, remember to be careful with your JWTs. Use strong cryptographic algorithms, manage those secret keys like they're
15 min read
Jun
30

JWT Patterns that provide real security benefits

Throughout this post we will keep an YUK WORD tally of things that are not security characteristics of JWT, that
15 min read
Jun
29

Really giving a jot about JWTs

Instacart Sr Security Engineer David Gillman (or Gilman? Either OWASP or LASCON got it wrong) presented a talk in 2021
2 min read
Jan
03

JWT and HMAC in the browser, safe?

Is using JWT and HMAC in the browser, safe? How could they be? Don't they require a pre-shared
3 min read