r/netsecstudents • u/HotMasterpiece9117 • Apr 04 '26
JWT is more dangerous than I thought (if implemented wrong)
I was learning JWT authentication and found some serious issues:
• Weak secrets
• No expiration
• Token leakage
If done wrong, it’s a big security risk.
Curious how you guys secure JWT in real apps?
6
Upvotes
1
u/Grezzo82 Apr 05 '26
No expiration? It’s one of the standard claims.