{"type":"rich","version":"1.0","author_name":"npub1j66aek8wm7jq8vaffs2l8w43evyywd4q7tcnqyge6xqezz0vcpks7jm42m","author_url":"https://nostr.ae/npub1j66aek8wm7jq8vaffs2l8w43evyywd4q7tcnqyge6xqezz0vcpks7jm42m","provider_name":"njump","provider_url":"https://nostr.ae","html":"📅 Original date posted:2013-11-02\n📝 Original message:On 11/01/2013 10:01 PM, bitcoingrant at gmx.com wrote:\n\n\u003e Server provides a token for the client to sign.\n\nAnyone else concerned about signing an arbitrary string?  Could be a\nhash of $EVIL_DOCUMENT, no?  I'd want to XOR the string with my own\nrandomly generated nonce, sign that, then pass the nonce and the\nsignature back to the server for verification.\n\n-- \nJohnathan Corgan, Corgan Labs\nSDR Training and Development Services\nhttp://corganlabs.com\n-------------- next part --------------\nA non-text attachment was scrubbed...\nName: johnathan.vcf\nType: text/x-vcard\nSize: 334 bytes\nDesc: not available\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20131102/09685fb5/attachment.vcf\u003e\n-------------- next part --------------\nA non-text attachment was scrubbed...\nName: signature.asc\nType: application/pgp-signature\nSize: 230 bytes\nDesc: OpenPGP digital signature\nURL: \u003chttp://lists.linuxfoundation.org/pipermail/bitcoin-dev/attachments/20131102/09685fb5/attachment.sig\u003e"}
