Author: Tech Support

Critical flaw alert! Stop using JSON encryption

A vulnerability in a JSON-based web encryption protocol could allow attackers to retrieve private keys. Cryptography experts have advised against developers using JSON Web Encryption (JWE) in their applications in the past, and this vulnerability illustrates those very dangers. Software libraries implementing the JWE, or RFC 7516, specification suffer from a classic Invalid Curve Attack,

Read More