|
|
|
|
|
by jupenur
2014 days ago
|
|
Blog author here; Russell's implementation is backed by github.com/beevik/etree, but like you said, it's just an interface. The tokenizer is still encoding/xml. Adding better support for namespaces and providing APIs compatible with dsig doesn't remove the underlying vulnerabilities. |
|