Toot

Written by Robert Gützkow on 2025-01-15 at 21:18

@sj @dangoodin the signature should be validated with a key that you know belongs to the legitimate sender. If you just use the public key that is contained within the very same message you are trying to validate then what is stopping an attacker from supplying a key of their choice?

=> More informations about this toot | View the thread | More toots from robertguetzkow@infosec.exchange

Mentions

=> View sj@social.scriptjunkie.us profile | View dangoodin@infosec.exchange profile

Tags

Proxy Information
Original URL
gemini://mastogem.picasoft.net/toot/113834454663595792
Status Code
Success (20)
Meta
text/gemini
Capsule Response Time
355.129389 milliseconds
Gemini-to-HTML Time
0.606397 milliseconds

This content has been proxied by September (3851b).