Why “attacker” is being discussed
The most recent Hacker News stories and comments contributing to this topic's mentions.
Or maybe it does include the important info at sign time, but the attacker adds additional info that confuses the program parsing the document.
by bawolff · Sep 22, 2026
My favourite SAML horror story, is that it used to be, that by default the main c implementation of xmlsig would not just check the sig with the public key specified but would a…
by bawolff · Sep 22, 2026
Normally you sign the whole dicument. In SAML you sign a (potentially attacker controlled) subset after normalization. So a lot of saml bugs come down to the attacker adding thi…
by bawolff · Sep 22, 2026
The reason that you get 3-4 bits of entropy per hash is because of the fundamental nature of CPUs. In addition to having considerable professional experience with cryptography,…
by Taek · Sep 22, 2026
I ran it 500,000 times, discarding the 10% most entropic results ... in the hopes of arriving at a relatively conservative estimate for the amount of entropy you actually get fr…
by Taek · Sep 22, 2026
Right, so your starting point is that the attacker has read-only access to ALL entropy sources, and in that scenario it's worse if the attacker has read-write access to one entr…
by knorker · Sep 22, 2026
Interest
Proportion of Hacker News items mentioning "attacker" over time.
Mentions
Total number of Hacker News items mentioning "attacker" over time.
In some team sports, an attacker is a specific type of player, usually involved in aggressive play. Heavy attackers are, usually, placed up front: their goal is to score the most possible points for the team. In association football, attackers are also referred to as forwards or strikers. Read more on Wikipedia