Case F31365 · Web AppSec · L3 Applied
JWT Pitfalls
Practise as: Explain it · Interview
Interview questionWhat are the most common ways JWT-based authentication goes wrong?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- alg:none accepted by a lax library lets attackers strip the signature and forge claims
- Algorithm confusion: RS256 public key used as an HS256 HMAC secret if the verifier trusts the header alg
- Weak HS256 secrets are crackable offline with hashcat; kid/jku/x5u headers can point to attacker keys
- JWTs are signed not encrypted; payload is base64url and readable, so never store secrets in claims
- Stateless tokens are hard to revoke: use short exp, validate aud/iss, and rotate via refresh tokens
If the interviewer pushes back
- How would you implement logout or forced revocation for JWTs without losing the benefits of statelessness?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.