Skip to Content [alt-c]
In reply to Duplicate Signature Key Selection Attack in Let's Encrypt
I feel like I'm missing something here. An attacker can craft a private key P and a message M, such that the signature of M signed with P is the same as the signature of some other message signed with some other private key? But what good does this do them? The signature of that other message won't be correct for their new message?
Your comment will be public. To contact me privately, email me. Please keep your comment polite, on-topic, and comprehensible. Your comment may be held for moderation before being published.
Your Name: (Optional; will be published)
Your Email Address: (Optional; will not be published)
Your Website: (Optional; will be published)
Post a Reply
Your comment will be public. To contact me privately, email me. Please keep your comment polite, on-topic, and comprehensible. Your comment may be held for moderation before being published.