>But the PKCS#1 spec talks about building up the complete padded signature
>input at the verifier, and then comparing it.

Uhh, did you actually read the rest of my post?  *One variant of the PKCS #1
spec, that didn't exist at the time the the affected other standards were
created*, talks about ..., not "the PKCS #1 spec" as a whole.  I even quoted
the original text of the spec in my message.


