I just interviewed <@U0255AJDA1Y> and we discussed...
# general
g
I just interviewed @Buchi Reddy Busi Reddy and we discussed API security. It was a good discussion. He promised to share here any OSS tools for validating infrastructure security. I promised to share all the discussions on Hacker News about JWT being insecure. Context: Buchi and myself agreed that JWT can be secure if used correctly, and discussed some best practices for this. In fact, this is the main take away from all of the discussions below too. But there is just a lot of FUD going around. So I am sharing these links in the interests of having everyone educate themselves. JWT tokens are the de-facto way machine-to-machine authentication works today, and are extremely popular for browser-based session cookies too. It isn't about whether or not you will use them (everyone does and you'll have no choice), it is about how to use them. https://news.ycombinator.com/item?id=33018135 <- from this week (!) https://news.ycombinator.com/item?id=21783303 <- has lot more links in the first comment https://news.ycombinator.com/item?id=18804875 <- this has comments from tptacek, which are the most frequently cited objections to JWT (but also the least balanced, IMO) https://news.ycombinator.com/item?id=27136539 https://news.ycombinator.com/item?id=24346317 <- A bit funny, it has been 249 days since the last JWT vulnerability... About the same as Log4J? Lots more: https://hn.algolia.com/?dateRange=all&amp;page=0&amp;prefix=false&amp;query=jwt&amp;sort=byPopularity&amp;type=story And more on Macaroons, which try to replace JWT in some contexts. So far, not very successfully: https://hackingdistributed.com/2014/05/16/macaroons-are-better-than-cookies/ <- The blog is by Emin GΓΌn Sirer, one of the most respected distributed crypto researchers.
πŸ‘€ 1
πŸ‘ 2
b
Oh wow.. thanks for sharing the links with me @Gwen Shapira this is a solid weekend read actually.
g
It gets repetitive. You'll see the main points after 1-2h πŸ™‚
s
This is great! Thanks for sharing Gwen. We consolidated a list of OSS DevSec tools. It includes security principles and controls relevant to popular compliance certifications πŸ‘‡ https://github.com/boxyhq/awesome-oss-devsec
πŸ‘ 2