I don't think this code protects against even the e=3 broadcast attack, because it doesn't verify the padding (as someone downthread noticed; I owe him a sticker now too).
Of course, not verifying the padding also means the signatures are straightforward to forge.
(Ping me with a shipping address and I'll send you swag).
Of course, not verifying the padding also means the signatures are straightforward to forge.
(Ping me with a shipping address and I'll send you swag).