flames5123@lemmy.worldtoLemmy@lemmy.ml•With the recent hack, there is now irrefutable proof of malicious actors trying to break Lemmy and steal user accounts. Please be careful about entering your password into random Lemmy apps!English
5·
1 year agoThe decoding algorithm can change, which is exactly what happened, invalidating all previously generated tokens. They cannot be decoded to a password though since they are encrypted, meaning shared passwords wouldn’t be an issue (though you should use a password manager to not have this issue in the first place).
Right. I was simplifying it by saying it was encrypted, but it’s just an auth token from the service after verifying that the user is authenticated.
And correct. I’m just an idiot and didn’t do research to explain it, even though I’ve used JWT tokens in my applications before. Hahaha. Thanks for the detailed correction!