6 ms·
That might have been the only text that allowed the updated to be signed.
by buffoon 11y ago
That might have been the only text that allowed the updated to be signed.
- dpark 11y agoThat's an interesting theory, but seems unlikely given that the TLDs are all real. Also that would imply a successful hash collision attack which seems exceedingly unlikely. And if true, why not mutate some random bytes in the payload to get the collision rather than the update text (which also may not actually even be stored as part of the signed update).