Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Most JWT libraries require to hardcode the expected algorithm when verifying a token, so if your applications are verifying the token provided by Auth0 with a JWT library, they're most likely not vulnerable to this mistake.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: