Hacker News new | ask | show | jobs
by mjg59 270 days ago
No, the modified copy included the same certificate page simply because it was a modified copy of the PDF with the certificate page. There's no actual way I've determined to verify the signed checksum field.
1 comments

Ah, so the 'signed checksum' field isn't actually the checksum of the signed document? How odd . . . but yeah, now that I think about it, they couldn't know the hash of a document before they generate it, but they would need to in order to include it in the document, hence an impossible cycle; they must have overlooked that . . .
Right, it's the hash of the document before they add the certificate page, but unfortunately there's no easy way to extract that to calculate it