Hacker News new | past | comments | ask | show | jobs | submit login

They tested XSW attacks against OOXML and couldn't find any, but yes, this line of attacks and XSW both sort of follow from the malleability/flexibility of XML. It's generally not secure to build signature systems "inside" of XML.



Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: