DEV Community

Discussion on: JWT explained in 4 minutes (With Visuals)

Collapse
 
mkulak profile image
Misha

You described MITM attack where malicious proxy can read and modify arbitrary data between client and server. If client sends back to the server jwt token for verification, what prevents proxy from intercepting this request and spoofing the response?

Collapse
 
nigel447 profile image
nigel447 • Edited

u are correct nothing stops this,hopefully you can see that just trusting that the jwt is valid is an error, basic idea is if you get a jwt that does not verify on the server then this is a red flag that you are under attack and you then implement defensive code, which is better than just hoping everything is ok, as to spoofing the response need correct headers