‹ BackHN Continuity

Thread

Keys Not Included: recovering the signing keys for US driver's license barcodes

289 points · 152 comments · Ryan5453

  1. EPWN3D · · focus · HN ↗
    > Before signing, the encoder fills the field with a placeholder (0), repeated for the field's exact length - signs the entire payload including that placeholder, and then writes the real signature over the top of it. To verify, you put the placeholder back.

    I hate shit like this. Do not let your crypto layer know about the structure of what it's signing. Keep security stupid.

    1. lazide · · focus · HN ↗
      Counterpoint - every real world crypto algo needs to do somewhat content aware padding or the crypto is much easier to break. Either that, or go so overboard on randomness that it adds a lot of overhead.

      When you look at the details underneath more crypto, there is a lot of ah hah - and ‘doh’ - moments due to implementation realities.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.