Start networking and exchanging professional insights

Register now or log in to join your professional community.

Follow

What are your perspectives on securing auth Tokens generated from a token based authentication system like JWT?

When a client authenticates with token based authentication, the server responds with a signed token, since the client has the token at hand, that authenticated client can still use the same token (from a different machine) or browser before the token expires!

Some developers store tokens in local storage which in insecure! I have heard suggestion to store the token in an encrypted cookie! but that still is insecure, how do we guarantee the authenticity of the client?

If a Key is provided to a client, that key can be missued and abused! whats the protection against this?

user-image
Question added by Ali Joudeh , Senior Full Stack Developer , Derq Systems FZ LLC
Date Posted: 2017/06/29
Ajidahun Desmond
by Ajidahun Desmond , Studio manager , Xds xcel digital solution

If your manger is not up to what is expected from him, then you have to be careful while doing work and take thing easy...

 

More Questions Like This