logoalt Hacker News

kukkamariotoday at 8:08 AM1 replyview on HN

The point of the checksum is to just drop obviously wrong keys. No need to handle revocation or do any DB access if checksum is incorrect, the key can just be rejected.


Replies

ben-schaaftoday at 1:19 PM

That sounds like it's only helpful for ddos mitigation, in which case the attacker could trivially synthesize a correct checksum.

show 1 reply