Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
jeffrallen
70 days ago
|
parent
|
context
|
favorite
| on:
Signing data structures the wrong way
It's a big if because the threat model normally includes "bad guys can forge messages". Which means that the input is untrusted and you want to generate your own domain separation bytes for the hash function, not let your attacker choose them.
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: