‹ BackHN Continuity

Thread

Keys Not Included: recovering the signing keys for US driver's license barcodes

289 points · 152 comments · Ryan5453

  1. EPWN3D · · focus · HN ↗
    > Before signing, the encoder fills the field with a placeholder (0), repeated for the field's exact length - signs the entire payload including that placeholder, and then writes the real signature over the top of it. To verify, you put the placeholder back.

    I hate shit like this. Do not let your crypto layer know about the structure of what it's signing. Keep security stupid.

    1. woodruffw · · focus · HN ↗
      As far as compact encodings go, this kind of patch-and-fill technique isn't particularly egregious. The alternative mentioned (where the verifier has to be aware of a bitfield that defines the to-be-signed elements) is much easier to mess up!
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.