Skip to content

Comment on How (not) to sign a JSON object (2019)

Comments

I really wish that XMLDSig wasn't such an awful standard that it turned a good third of the security industry against canonicalization in general.

Saying there's "sure there's lots of ways to serialize, but these specific rules get you the same octet and you sign that" is key to sanity in such situations.

For all of ASN.1's many sins, they got that part absolutely right.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.