Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

That's because its built in part on XMLDSig, a genius idea to sign active content that can redefine its own semantics as it's being signed/verified. It's a triumph of ideology over common sense.
 help



I think I got to the canonicalization part of the relevant spec and decided that life was too short...

NB I can absolutely see why canonicalization is required... just that it was the bit where I lost interest


The first book that came out on XMLDSig, "Secure XML: The New Syntax for Signatures and Encryption", written by the chair of the working group, spent over half of its 500 pages wrestling with canonicalization, and even then it read more as a 250-page problem statement than a solution.

And that was before you got into deliberately malicious content that actively subverts the signature process.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: