Alright, so just because a plain text signature is along with content, doesn't mean that the content is signed.
Then how do you check that the content is signed by the plain-text signature given with it?
I thought that the signature means that either a whole copy of the text is encrypted or a hash of the text is encrypted using the private key, which would mean that spoofing the sign would require solving complexity equal to either of:
- Finding another string that gives the same hash
- Finding the private key and signing a new hash with it
What am I missing?