Live data from Hacker News

Spoofing OpenPGP.js signature verification

codeanlabs.com

31–32 of 32 posts

Re: Spoofing OpenPGP.js signature verification

#31
post #26
post #25

Earlier quoted context omitted.

with that argument TLS would be insecure, because there are insecure TLS implementations.

That's not the argument, it's that it's a bad design repeatedly shown to be shown to be prone to serious vulnerabilities and it's silly to argue it's not a bad design at yet another such time. People have made serious arguments for all sorts of design problems in SSL/TLS.

the design is not bad per se. pgp is just a bit outdated and needs an overhaul.

And cryptographic serialization is just difficult.

Re: Spoofing OpenPGP.js signature verification

#32
post #31
post #26

Earlier quoted context omitted.

That's not the argument, it's that it's a bad design repeatedly shown to be shown to be prone to serious vulnerabilities and it's silly to argue it's not a bad design at yet another such time. People have made serious arguments for all sorts of design problems in SSL/TLS.

the design is not bad per se. pgp is just a bit outdated and needs an overhaul. And cryptographic serialization is just difficult.

It's not resting, it's dead.
Post reply on HN