No Way, JOSE! Javascript Object Signing and Encryption is a Bad Standard That Everyone Should Avoid
Scott Arciszewski, Paragon Initiative Enterprises Blog, 2018/01/17
I have no position on the issue described in this post because it's all new to me. But because it's all new to me it's inherently interesting, and the discussion perhaps points the way to the future of signing and encrypting Javascript objects (such as data or executable code). The argument here against Javascript Object Signing and Encryption (JOSE) is that it is often abused, and that it makes forgery trivial. More...