Remix.run Logo
dzonga 9 hours ago

due to the recent FIFA hack - just a reminder - stop using JWTs

dgrin91 8 hours ago | parent | next [-]

The Fifa hack had nothing to do with JWTs, it was because FIFA was doing auth on the client side. They would have had the same issue if they used cookie auth.

mycall 8 hours ago | parent [-]

h4ckernews also accessed an Azure Function App that provided direct download URLs for internal FIFA files, including transfer reports and board level data, due to a lack of RBAC access checks.

tancop 6 hours ago | parent | prev [-]

if you are fifa please keep using them in the most insecure way possible. release the infantino files