Cursed idea:

JWTs that use bcrypt

With a 72-byte header

@soatok

DON' GIVE THEM IDEAS!

This is why we can't have nice things.

@soatok I raise you: "using JWT, but not really understanding them, therefore just accepting the data inside, but not actually verifying it" - which I may have seen in a project
@darkrat Hey guess what bcrypt does on inputs longer than 72 chars

@soatok

Supposed benefits of following soatok on fedi: An insight into the technology of digital security, with recommendations on what to use and what to avoid, for free

Actual benefits of following soatok on fedi: Cool fursuit pics, and enough of an insight into the technology of digital security to get the jokes of a whole new dimension of gross-out humor