|
|
|
|
|
by ivanbakel
2015 days ago
|
|
> that wasn't designed to support cryptographic security An XML library doesn't have to support cryptographic security - it just has to perform XML en/decoding effectively. How can it be a mistake for a project to rely on part of the standard library? |
|
Just to clear it up and state it plainly: it is never reasonable to assume that a given XML library is suitable for building XMLDSIG on top of or alongside.