(1/x) Spain's largest online card processor: * XML inside XML * Signing XML as text: cannot use a real XML parser or the signature breaks
-
-
(3/x) * Signing key is pre-diversified in a dumb way for no reason, reducing entropy * CBC mode with all-0 IV
-
(4/x) * Their reference manual is useless (no mention of modes, IVs, etc): only way to interoperate is to reverse engineer their sample API.
- Show replies
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.