Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You didn't read carefully enough.

Your site may well find both HMAC and RSA to be acceptable algorithms. However if you can be tricked into using HMAC to verify something actually signed with RSA, then anyone can forge content you accept as valid.

What is important is not that the algorithm is acceptable. It is that the algorithm you use for verification is the algorithm that actually should be used.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: