github.com/lestrrat-go/jwx/v4 is going to lose jwk fetching from its core. Don't worry, it will be available -- but it will be available via companion modules that allows us to create extensions to jwx proper. Also added Hybrid HPKE, Composite Signatures.

I'm _very_ close to cutting a v4.0.0 release. Probably going to cut an alpha, a beta, then v4.0.0 proper

https://github.com/lestrrat-go/jwx/discussions/1673
https://github.com/lestrrat-go/jwx/blob/develop/v4/Changes-v4.md

#golang #jwt #jws #jwe #jwk

Announcing github.com/lestrrat-go/jwx/v4 (Preview) · lestrrat-go jwx · Discussion #1673

github.com/lestrrat-go/jwx/v4 is under active development and I'm looking for early feedback. This is a major release that rethinks how jwx is structured, with three goals: make it faster, make it ...

GitHub
Announcing github.com/lestrrat-go/jwx/v4 (Preview) · lestrrat-go jwx · Discussion #1673

github.com/lestrrat-go/jwx/v4 is under active development and I'm looking for early feedback. This is a major release that rethinks how jwx is structured, with three goals: make it faster, make it ...

GitHub

I created jws.app

I created this to announce crap that I created (like Photos.JWS or GIFs.JWS). Don’t expect much to be posted here.

🔐 MANIFIESTO DE AUTORÍA – ZAPATILLAZO DIGITAL
Por Roberto Magdalena García – cMd_p1nG
En los últimos días hemos detectado el uso del término “Zapatillazo Digital” en entornos corporativos y documentación técnica sin la debida atribución.
Dejo constancia pública de que el concepto, manifiesto y visión de “Zapatillazo Digital” fueron creados como parte del proyecto Eternal Reserve, un marco cultural y técnico desarrollado por mí,
Roberto Magdalena García, alias cMd_p1nG.
Esta obra fue concebida en 2023 como una respuesta ética y rebelde al control sobre los activos digitales,
y no está asociada a ninguna corporación, proveedor cloud ni plataforma comercial.
Cualquier intento de apropiación no autorizada será considerado una violación de propiedad intelectual e identidad narrativa.
Por la verdad digital.
Por los que firmamos con barro y no con trajes.
📜 Certificado: Eternal Reserve CA
🔐 UUID: e6f0b2a7-c8d4-4e1f-8a0b-1c5d9e0f3a4b
🧾 Hash del manifiesto original:
a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2

#ZapatillazoDigital
#EternalReserve
#cMd_p1nG
#IdentidadDigital
#FirmaDigital
#Criptografía
#PropiedadIntelectual
#BlockchainEthics
#CertificadoDigital
#CyberSecurity
#DigitalSovereignty
#PEM
#JWS
#OpenStandards
#CloudSecurity
#DigitalPreservation
#InfoSec
#HackerCulture
#RebeldíaDigital
#CódigoConAlma
#ResistenciaTech
#ManifiestoDigital
#Originalidad
#ElCódigoEsPoesía
#SelloDeAutor
#LinkedInTech
#Innovación
#FuturoDigital #TransformaciónDigital
#TecnologíaConSentido

🎉 v3.0.0 released · lestrrat-go jwx · Discussion #1335

🎉 v3.0.0 has been released! v3 further streamlines the API for flexibility and ease of use. While all packages received significant updates, the jwk package has gone through the most significant ch...

GitHub
Release OpenWebStart v1.11.0 · karakun/OpenWebStart

This release provides the following improvements: Update bundled JRE to jdk8u432-b06 Allow installation specific deployment.properties file to configure OWS. The local deployment.properties file p...

GitHub
Jehovah’s Witness Sues Country for Receiving Life-Saving Blood Transfusion Against Her Will

A Jehova's Witness has taken the country of Spain to the European Court of Human Rights for administering her a blood transfusion during surgery against her will

Oddity Central

Scott Arciszewski's post on How to Write a Secure JWT Library If You Absolutely Must: https://scottarc.blog/2023/09/06/how-to-write-a-secure-jwt-library-if-you-absolutely-must/

#jwt #jsonwebtoken #cryptography #jws

How to Write a Secure JWT Library If You Absolutely Must

I am famously not a fan of JSON Web Tokens (JWT). Like most cryptography and security experts familiar with JWT, I would much rather you use something else if you can. I even proposed a secure alte…

Semantically Secure
exJW - lemm.ee

Just dropped our paper on eprint: OpenPubkey. I welcome any questions/feedback replies

#OpenPubkey adds user-held public keys into OpenID Connect without breaking compatibility. This means users can create digital signatures on the web that are associated with their ID Tokens. Fully signed APIs here we come.

Our protocol is so compatible with existing IDPs that not only have we been using it in production with Google, Okta, and Microsoft IDPs for over a year, but that IDPs can't even tell that OpenPubkey is being used!

#OIDC #JSON #JWS #websec

https://eprint.iacr.org/2023/296.pdf