How (not) to sign a JSON object
https://latacora.micro.blog/2019/07/24/how-not-to.html [latacora.micro.blog]
2019-07-24 17:19
This covers a lot of ground. I liked this quote, even though there’s much more to the post.
Canonicalization is a quagnet, which is a term of art in vulnerability research meaning quagmire and vulnerability magnet. You can tell it’s bad just by how hard it is to type ‘canonicalization’.
source: HN