{"id":17,"count":4,"description":"<p>These posts exist because a lot of confident security advice is wrong, and the wrong parts are dangerous.<\/p>\r\n<p>A worked example: a JWT signature proves the token was issued by someone holding the key. It does not prove the token is still valid, it does not encrypt the payload, and anyone can read the claims in it with a Base64 decoder. People routinely assume all three of those are false. The post on JWTs is mostly about that gap.<\/p>\r\n<p>Elsewhere: why bcrypt is deliberately slow and why that slowness is the feature, not a bug to be optimised away. Why MD5 is fine for a checksum and catastrophic for a password. What entropy means for a password \u2014 measurably, in bits \u2014 and why a memorable passphrase can beat <code>P@ssw0rd!<\/code> by a wide margin. Why a UUIDv4 is random and a UUIDv1 leaks a timestamp and a MAC address.<\/p>\r\n<p>For developers who inherited an auth system and need to judge it. Decode a real token in the <a href=\"https:\/\/schoolict.net\/tools\/jwt-decoder-inspector\/\">JWT Studio<\/a> while you read \u2014 it lands harder than a diagram.<\/p>","link":"https:\/\/schoolict.net\/tools\/security-tools\/","name":"Security Tools","slug":"security-tools","taxonomy":"category","parent":0,"meta":[],"_links":{"self":[{"href":"https:\/\/schoolict.net\/tools\/wp-json\/wp\/v2\/categories\/17","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/schoolict.net\/tools\/wp-json\/wp\/v2\/categories"}],"about":[{"href":"https:\/\/schoolict.net\/tools\/wp-json\/wp\/v2\/taxonomies\/category"}],"wp:post_type":[{"href":"https:\/\/schoolict.net\/tools\/wp-json\/wp\/v2\/posts?categories=17"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}