brian m. carlson
2017-02-13 00:59:28 UTC
There was some question as to whether we should use four-octet or
eight-octet lengths for signatures (or some other technique), as one
might want to sign more the 2^32 bytes of data. I've submitted a pull
request[0] to use eight-octet lengths for all signatures.
I don't think the overhead of hashing an additional four bytes for short
signatures will matter, and I feel that simply overflowing the existing
four-byte counter could potentially collision issues down the line.
Other opinions are welcomed.
[0] https://gitlab.com/openpgp-wg/rfc4880bis/merge_requests/1
eight-octet lengths for signatures (or some other technique), as one
might want to sign more the 2^32 bytes of data. I've submitted a pull
request[0] to use eight-octet lengths for all signatures.
I don't think the overhead of hashing an additional four bytes for short
signatures will matter, and I feel that simply overflowing the existing
four-byte counter could potentially collision issues down the line.
Other opinions are welcomed.
[0] https://gitlab.com/openpgp-wg/rfc4880bis/merge_requests/1
--
brian m. carlson / brian with sandals: Houston, Texas, US
+1 832 623 2791 | https://www.crustytoothpaste.net/~bmc | My opinion only
OpenPGP: https://keybase.io/bk2204
brian m. carlson / brian with sandals: Houston, Texas, US
+1 832 623 2791 | https://www.crustytoothpaste.net/~bmc | My opinion only
OpenPGP: https://keybase.io/bk2204