Hacker News new | past | comments | ask | show | jobs | submit login

JWTs are definitely a much larger surface area than simpler encrypted sessions storage and most people don’t need that.

I cited this as one example of that surface area that led to serious vulnerabilities. Most people don’t need multiple ways to encrypt their data, and certainly not a ‘no encryption’ option. Each added option adds more ways to mess things up.




Consider applying for YC's first-ever Fall batch! Applications are open till Aug 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: