Algorithm Confusion

Also known as:Key Confusion

Algorithm Confusion: Attack in which the verifier accepts a signature algorithm chosen by the attacker. The class became widely known through JSON Web TokensJSON Web TokenCompact, signable token for transmitting identity and authorization information., whose header names the algorithm itself.

How it works and where it fits

A JWT carries its algorithm in the alg field — precisely the part the attacker controls. If the verifying library reads that value instead of pinning it server-side, verification can be reinterpreted. The classic case switches RS256 to HS256: the server actually signs asymmetrically with a private key but now verifies symmetrically, using the public key as the HMAC secret. Since that key is public by definition, the attacker can sign arbitrary claims. The alg: none variant drops the signature altogether.

Practical security relevance

The protection is unambiguous and cheap: pin the permitted algorithm server-side and pass it explicitly during verification, and keep keys separated per scheme. An exposed public key is unproblematic in a correct implementation — only the confusion turns it into an attack vector. When testing, the exact byte format of the key matters, because the server uses precisely the representation it reads in as its secret.

  • JSON Web TokenJSON Web TokenCompact, signable token for transmitting identity and authorization information.: Compact, signable token for transmitting identity and authorization information.
  • Digital SignatureDigital SignatureCryptographic proof of the authenticity and integrity of digital data.: Cryptographic proof of the authenticity and integrity of digital data.
  • AuthenticationAuthenticationVerification of the claimed identity of a user or system.: Verification of the claimed identity of a user or system.
  • Cryptographic AlgorithmCryptographic AlgorithmA formally defined computation used for encryption, signatures, hashing, or key establishment.: A formally defined computation used for encryption, signatures, hashing, or key establishment.