Open cardosec

Case F31365 · Web AppSec · L3 Applied

JWT Pitfalls

Practise as: Explain it · Interview

Interview questionWhat are the most common ways JWT-based authentication goes wrong?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. alg:none accepted by a lax library lets attackers strip the signature and forge claims
  2. Algorithm confusion: RS256 public key used as an HS256 HMAC secret if the verifier trusts the header alg
  3. Weak HS256 secrets are crackable offline with hashcat; kid/jku/x5u headers can point to attacker keys
  4. JWTs are signed not encrypted; payload is base64url and readable, so never store secrets in claims
  5. Stateless tokens are hard to revoke: use short exp, validate aud/iss, and rotate via refresh tokens

If the interviewer pushes back

  • How would you implement logout or forced revocation for JWTs without losing the benefits of statelessness?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.