Missing Signature (v0.2)

A v0.2 manifest with no signature block. Two entities: an attacker sends and a verifier detects the stripping attack.

Stripping Attacker

Sends a v0.2 manifest with the signature block removed.

SITE

Signature Verifier

Requires signature presence for v0.2 and rejects signature-stripping attempts.

CONSUMER
Subject: A v0.2 manifest with no signature block -- a signature stripping attack.
4 steps