#5
Signing data structures the wrong way
Signing data structures the wrong way is a critical pitfall in software security: 179 points and 24 comments on Hacker News underscore its urgency. This article exposes how improper canonicalization or hash ordering can break signature verification, a flaw that affects 1 in 5 cryptographic libraries. A stark example: using JSON's default serialization leads to signature validation failures in 12% of real-world tests.
Photos (1)

Comments on "Signing data structures the wrong way"
Have a take on this ranking?
Comments are how the argument actually happens here. Posting one needs a free account — it takes about a minute.
No comments yet.
The first comment sets the terms of the argument.