| ▲ | BaconVonPork 2 days ago | ||||||||||||||||
You are saying people shouldn't want what they want and since JSON has no standards for it you assume it won't happen. Not even X509 is interested in working with detached signatures. > It does not matter whether your serialization is canonical or not if you don't need to parse the document before you've verified the signature on it. It most certainly does. First or last duplicate key? | |||||||||||||||||
| ▲ | aleksejs 2 days ago | parent [-] | ||||||||||||||||
I am comfortable saying that, when designing a signature scheme, people should not want features that are known to consistently lead to catastrophic vulnerabilities. | |||||||||||||||||
| |||||||||||||||||