|
|
|
|
|
by woodruffw
925 days ago
|
|
> You can of course still manually add keys, and you can even do automatic or semi-automatic key rotation with some new header (e.g. "X-New-Key: [...]" that's signed with the old). Headers aren't part of an encrypted or authenticated body, so this is trivial to perform a key replacement attack against. |
|