Hacker News new | ask | show | jobs
by meowface 3642 days ago
All that really matters is that the outermost layer is signed, and that the signature is required to be properly verified by the recipient before any other processing is done.

Regardless of whether you're encrypting or compressing or signing twice or what order those are in.