[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [Chicken-hackers] CHICKEN in production
From: |
John Cowan |
Subject: |
Re: [Chicken-hackers] CHICKEN in production |
Date: |
Mon, 13 Oct 2014 21:07:12 -0400 |
User-agent: |
Mutt/1.5.20 (2009-06-14) |
Florian Zumbiehl scripsit:
> > I am frankly sick of tools bending over backwards to support NUL.
>
> I am frankly sick of people making up their own variants of standards,
> creating all kinds of interoperability and security problems, and even more
> of environments that make it unnecessarily difficult to implement
> conforming implementations.
Profiling a standard is hardly making up your own variant of it.
The Unicode Standard does not in fact require for conformance that a
system be able to process every character in it, and it is in fact quite
unusual for a system to be able to handle every character end to end.
> some creative person submits a JSON document with NULs to your frontend
> system, which validates it, passes it to your JSON-but-without-NULs
> parser, and voilà, you have a DoS, congrats!
Where does the DoS come in? Your back end quite legitimately rejects
such a bogus document, which is far better than having it accept it with
a truncated string. It's not, after all, a DoS to deny service to a
malicious actor.
--
John Cowan http://www.ccil.org/~cowan address@hidden
We do, doodley do, doodley do, doodley do,
What we must, muddily must, muddily must, muddily must;
Muddily do, muddily do, muddily do, muddily do,
Until we bust, bodily bust, bodily bust, bodily bust. --Bokonon
- Re: [Chicken-hackers] CHICKEN in production, (continued)
- Re: [Chicken-hackers] CHICKEN in production, Florian Zumbiehl, 2014/10/13
- Re: [Chicken-hackers] CHICKEN in production, John Cowan, 2014/10/13
- Re: [Chicken-hackers] CHICKEN in production, Florian Zumbiehl, 2014/10/13
- Re: [Chicken-hackers] CHICKEN in production, Alex Shinn, 2014/10/13
- Re: [Chicken-hackers] CHICKEN in production, Florian Zumbiehl, 2014/10/13
- Re: [Chicken-hackers] CHICKEN in production, Alex Shinn, 2014/10/13
- Re: [Chicken-hackers] CHICKEN in production,
John Cowan <=
- Re: [Chicken-hackers] CHICKEN in production, Florian Zumbiehl, 2014/10/13
- Re: [Chicken-hackers] CHICKEN in production, John Cowan, 2014/10/13
- Re: [Chicken-hackers] CHICKEN in production, Jörg F. Wittenberger, 2014/10/14
- Re: [Chicken-hackers] CHICKEN in production, Michele La Monaca, 2014/10/15
- Re: [Chicken-hackers] CHICKEN in production, John Cowan, 2014/10/15
- Re: [Chicken-hackers] CHICKEN in production, Peter Bex, 2014/10/16
- Re: [Chicken-hackers] CHICKEN in production, John Cowan, 2014/10/16
- Re: [Chicken-hackers] CHICKEN in production, Jörg F. Wittenberger, 2014/10/13
- Re: [Chicken-hackers] CHICKEN in production, Oleg Kolosov, 2014/10/08
- Re: [Chicken-hackers] CHICKEN in production, Jörg F. Wittenberger, 2014/10/10