security issue with signing files

Kent Tong kent@cpttm.org.mo
Sat Nov 24 16:39:01 2001


Dear all,

Suppose a user is about to sign a file that he has just viewed, but someone
else modifies the files over the network, then he will sign over the
arbitrary
contents written by anyone who has write access? How to solve this
problem? This is a common case when the superior is reviewing and signing
a document (in a shared project folder) created by a subordinate.

Thanks!