> Incorrect. What is covered by the digest is ABDE, but within ABDE is a > *signed* assertion that the only allowable difference between the document > and ABDE is the addition of C between B and D. Can you please > state why you think this is insecure? I don't think you can. I think this overcomplicates things and nobody, or not many, will understand that concept. This is as if we sign ABCDE and tell the user to ignore C. Doesn't make sense. Either we want to sign ABDE, then we should sign ABDE, and if we wnat to put C into the picture, why tell them that we don't want to sign it, but still do in some obscure way, indirectly maybe. Peter
This archive was generated by hypermail 2.2.0 + w3c-0.29 : Thursday, 13 January 2005 12:10:08 GMT