-
Notifications
You must be signed in to change notification settings - Fork 343
Open
Labels
bugSomething isn't workingSomething isn't workingtriagedIssues labeled as 'Triaged' have been reviewed and are deemed actionable.Issues labeled as 'Triaged' have been reviewed and are deemed actionable.
Description
Describe the bug
Hello,
this isn't exactly a bug but not a feature request at all either.
I'm planning to use JWT in production to validate users, rather than username and password and a question came to my mind:
How safe is JWT? Can it be used like a device token? I guess its private key is shared across different users and hence, if so, then, an adversary could leverage this, obtain several jwt signed by the same key and then use cryptographic methods to obtain the key?
Related component
Other
To Reproduce
Just activate JWT authentication, obtain several keys for several users and then use a brute-force approach to obtain the private key
Expected behavior
It should be safer
Additional Details
No response
Metadata
Metadata
Assignees
Labels
bugSomething isn't workingSomething isn't workingtriagedIssues labeled as 'Triaged' have been reviewed and are deemed actionable.Issues labeled as 'Triaged' have been reviewed and are deemed actionable.