| ▲ | bawolff a day ago | |||||||
Yes. JWT also had a bug where some implementations would use the pubkey as an hmac password if you switched the algorithm which is similarly bad. Specifying the algorithm in the attacker controlled document is a bad design imo. Still i feel like SAML is much worse. JWT has a few rough edges, but SAML its like everything. | ||||||||
| ▲ | patmorgan23 12 hours ago | parent [-] | |||||||
Yeah, the standard should have just specified like a sha256 HMAC, when that becomes broken in 20 years we can just do a JWT2 (or invent some new successor standard) | ||||||||
| ||||||||