🦞🌯 Lobster Roll

Thread

Critical vulnerabilities in JSON Web Token libraries (timmclean.net)

Stories related to "Critical vulnerabilities in JSON Web Token libraries" across the full archive.

Critical vulnerabilities in JSON Web Token libraries (timmclean.net)
Critical crypto bug in OpenSSL opens two-thirds of the Web to eavesdropping (arstechnica.com)
Using JSON Web Tokens to Authenticate JavaScript Front-Ends on Rails (zacstewart.com)
Inlining Critical CSS for Dynamic Web Apps (ponyfoo.com)
Multiple critical vulnerabilities in AVG "Web TuneUP" Chrome extension (9m users) (code.google.com)
Critical Web Fonts (zachleat.com)
JWT Inspector - Chrome extension to inspect and debug JSON Web Tokens (jwtinspector.io)
Using Hardware Token-based 2FA with the WebAuthn API (hacks.mozilla.org)
JSON Web Token Security Cheat Sheet (assets.pentesterlab.com)
Refresh Tokens in ASP.NET Core Web Api (blinkingcaret.com)
Stealing Webpages Rendered on Your Browser by Exploiting GPU Vulnerabilities (cc.gatech.edu)
Abstract: "Graphics processing units (GPUs) are important components of modern computing devices for not only graphics rendering, but also effcient parallel computations. However, their security problems are ignored despite their importance and popularity. In this paper, we frst perform an in-de...
Exploiting and Automated Detection of Vulnerabilities in Web Applications (2007) (zemris.fer.hr)
JSON Web Token Validation Bypass in Auth0 Authentication API (insomniasec.com)
JSON Web Token (JWT) RFC (tools.ietf.org)
What's in a JWT (Json Web Token)? (loige.co)
Web Hackers vs. The Auto Industry: Critical Vulnerabilities in Ferrari, BMW, Rolls Royce, Porsche, and More (samcurry.net)
I Love JWTs (JSON Web Tokens) (kerkour.com)
Understanding JSON Web Tokens (JWTs) (fusionauth.io)
Ten years of JSON Web Token and preparing for the future (self-issued.info)
EyJaafCsubstantially: Cramming English words into JSON web tokens (tesseral.com)
EyJaafCsubstantially: Cramming English words into JSON web tokens (tesseral.com)
RFC 9901: Selective Disclosure for JSON Web Tokens (rfc-editor.org)
RFC 9901: Selective Disclosure for JSON Web Tokens (rfc-editor.org)
Signing JSON Web Tokens: Algorithm Tradeoffs, Performance, and Security (ciamweekly.substack.com)
Signing JSON Web Tokens (ciamweekly.substack.com)
WebSocket+Huffman vs. SSE+JSON for streaming LLM tokens (github.com)
New Rule: Every website must disclose their password storage format on the signup page. (gizmodo.com)
Scared to disclose? It's too weak.
Web Performance Testing With PhantomJS (wesleyhales.com)
Neat way to leverage PhantomJS :)
Noir tutorial (web development with Clojure) (yogthos.net)
Amazon Web Services Blog: Amazon Glacier: Archival Storage for One Penny Per GB Per Month (aws.typepad.com)