You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
if somehow cracker knows I was using this lib then he watches the real created .lic file to know what fields my app was checking.
then he creates a .lic file using the same lib with his private key and passphrase and the same field structure. then I thought this fake .lic file would be accept in my app cause the above code would validate the fake one too!!!
Is there some misunderstood or something I need to change to make it right using the Lib?
The text was updated successfully, but these errors were encountered:
@dellos - you are signing with your private key, but you validate the signature with your public key. They are a pair. So, even if someone uses the same library with the same fields, etc, to generate a license file, unless they also had your private key to sign with, their license file will fail when you validate the signature with your public key.
if somehow cracker knows I was using this lib then he watches the real created .lic file to know what fields my app was checking.
then he creates a .lic file using the same lib with his private key and passphrase and the same field structure. then I thought this fake .lic file would be accept in my app cause the above code would validate the fake one too!!!
Is there some misunderstood or something I need to change to make it right using the Lib?
The text was updated successfully, but these errors were encountered: