RE: [ACTION-412][Fwd: Re: namespace wrapping attacks against XML Signature?]

Frederick Hirsch wrote on 2009-12-29:
> We probably should add more information on the issues related to
> prefix-rewriting to the requirements, with some examples like this. We
> need to be clear that it is not a complete explanation, but provide
> some information on the issues around the topic.

My point was just that unless I'm missing something, this isn't one of the
use cases or issues which rewriting helps. The only one I'm aware of is to
accommodate broken tools, actually.

-- Scott

Received on Tuesday, 29 December 2009 21:36:45 UTC