Skip to content

Comment on API Security Checklist for developersparent

Comments

Developers think that the data is encrypted, when it's only base64'd

Doesn't it depend on the specific implementation? For example I have been using github.com/dgrijalva/jwt-go package to build a token, add claims and sign it along with github.com/auth0/go-jwt-middleware to validate the requests. The JWT in that case is signed and encoded as a string using the secret.

jwt-go says right in the readme that it is not encrypted:

> It's important to know that JWT does not provide encryption, which means anyone who has access to the token can read its contents. <<

Okay, let's say that 3rd party read the user id which my app keeps in a JWT token. What would they do with it?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.