JSON Web Token Best Current Practices¶
Sheffer, Hardt, & Jones. (2020). JSON Web Token Best Current Practices.
Cited by¶
1 citation across 1 artifact.
Domain-specific¶
- Authentication Failure
- Credential theft and reuse — phishing, breached-credential stuffing against password reuse, and infostealer malware feeding stolen passwords into the front door. Weak or phishable factors — single-factor passwords, and SMS one-time passwords defeated by SIM-swap or interception. Token forgery — forged JWTs from algorithm-confusion bugs, signing-key disclosure, or downgrade attacks
Supported in partVerified against the work's full text
“The algorithm can be changed to "none" by an attacker, and some libraries would trust this value and "validate" the JWT without checking any signature.”
- Credential theft and reuse — phishing, breached-credential stuffing against password reuse, and infostealer malware feeding stolen passwords into the front door. Weak or phishable factors — single-factor passwords, and SMS one-time passwords defeated by SIM-swap or interception. Token forgery — forged JWTs from algorithm-confusion bugs, signing-key disclosure, or downgrade attacks
Verification¶
Does it exist? Confirmed. This work's DOI resolves to a registered record, which fixes its identity. That is all it fixes.
Does it back the claim? Read against the text for 1 of 1 citation: 1 supported in part. Each verdict is shown under its citation below, with what in the work backs the sentence.
Support is checked per citation rather than per work — the same source can be cited soundly in one article and wrongly in another. Per-citation recording began recently, so a citation with no recorded check is a gap in the record rather than evidence it went unchecked.
See how references were verified.
Registry ID ref:195369452a62 · see in the full table