Coze
paseto
Coze | paseto | |
---|---|---|
27 | 26 | |
103 | 3,188 | |
0.0% | -0.2% | |
6.1 | 4.7 | |
about 2 months ago | 7 days ago | |
Go | PHP | |
BSD 3-clause "New" or "Revised" License | GNU General Public License v3.0 or later |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Coze
-
JSON Web Proofs
https://cyphr.me/coze#?input={%22pay%22:{%22msg%22:%22Hello,...
-
Hype Will Turn Your Security Key into Junk
We're working on an open source alternative to Passkeys starting with Coze https://github.com/Cyphrme/Coze.
We have not yet published our next steps, but we will soon.
-
Introducing Coze - a cryptographic JSON messaging specification
You can play with Coze here using the online tool. There is also the simple tool.
- Show HN: Coze – cryptographic JSON messaging specification
-
Coze: a cryptographic JSON messaging specification designed for human readability
Base64 also has problems, in particular with canonicalization. This is a problem that I think needs more awareness in the industry. It does seem to recently gained some awareness (See the paper, "Base64 Malleability in Practice")
-
Daily General Discussion - July 10, 2023
Coze is a cryptographic JSON messaging specification designed for human readability.
-
Passage by 1Password
Our website is already using public key authentication using Coze. https://github.com/Cyphrme/Coze. We've been doing public key authentication for around 2 years now. No passwords needed, just public key auth.
-
Passkeys: The Beginning of the End of the Password
On my website, I'm doing authentication via simple public key authentication using Coze.
No passwords. No email. No Google. https://github.com/Cyphrme/Coze
paseto
-
JSON Web Proofs
Might I suggest Paseto (https://paseto.io/) - it solves a lot of the headaches of JWT. Signing and encryption are two different things that require two different sets of keys, so you can't mess it up.
(Full disclosure, I've written one implementation: https://github.com/auth70/paseto-ts)
-
Full-stack authentication system using rust (actix-web) and sveltekit
Though we'll be building a session-based authentication system, it's noteworthy that with the introduction of some concepts which will be discussed in due time, you can turn it into JWT- or, more securely and appropriately, PASETO-based authentication system.
- Biscuit 3.0
-
Securing Your Golang Application: Unleashing the Power of Authentication and Authorization
Time we ditch it and use paseto
- Paseto is everything you love about JWT without any of the design deficits
- Why JWTs Suck as Session Tokens (2017)
-
Looking for advice for Go Backend REST API for a Front End React/NodeJS
The PASETO web site goes over it. Mostly it's designed to make you do things the right way and avoid all the security holes you can fall into with JWT.
- Initial impact report about this week's EdDSA Double-PubKey Oracle attack in 40 affected crypto libs
-
Stop Storing Authentication Tokens in JS-accessible Storage
If this is too much to handle, you shouldn't have to! There's already solutions that handle it for you
What are some alternatives?
rust-u2f - U2F security token emulator written in Rust
branca - :key: Secure alternative to JWT. Authenticated Encrypted API Tokens for Go.
openpgpjs - OpenPGP implementation for JavaScript
Symfony Panther - A browser testing and web crawling library for PHP and Symfony
ITCB-master - One Repo to Find Them, and In the Darkness, Bind Them
wp-graphql-jwt-authentication - Authentication for WPGraphQL using JWT (JSON Web Tokens)
OpenSK - OpenSK is an open-source implementation for security keys written in Rust that supports both FIDO U2F and FIDO2 standards.
Ory Hydra - OpenID Certified™ OpenID Connect and OAuth Provider written in Go - cloud native, security-first, open source API security for your infrastructure. SDKs for any language. Works with Hardware Security Modules. Compatible with MITREid.
fido2 - Open-source FIDO server, featuring the FIDO2 standard. https://demo4.strongkey.com/getstarted/#/openapi/fido
php-jwt - PHP package for JWT
eth-wizard - An Ethereum validator installation wizard
bubble - bubble 旨在为项目快速开发提供一系列的基础能力,方便使用者根据项目需求快速进行功能拓展。已将所有 JAR 包都推送至中央仓库,也会为每个版本的升级改动列出详细的更新日志