Hacker News new | ask | show | jobs
by srfilipek 2084 days ago
The article discusses interoperability issues; it isn't an attack or vulnerability.

The issue is that implementations will reject valid signatures.

1 comments

Yeah, sorry, my wording wasn’t clear. I meant that attacks exist based on not utilising appropriate validation criteria (and, for example, libsodium’s more strict criteria do indeed prevent them).
Which attack(s) would that be?