3 ms·
> 2. Perform server-side, not client-side validation, WhatsApp is end to end encrypted, so how is server side validation possible?
by ploggingdev 10y ago
> 2. Perform server-side, not client-side validation,
WhatsApp is end to end encrypted, so how is server side validation possible?
- dsacco 10y agoIt's not :) I was being prescriptive about general purpose applications, sorry! In this specific scenario, the files should be validated before a user is presented with them and after they are received and decrypted. The client-side validation is only so that the attacker cannot bypass it and leave the server vulnerable; you can instead offload this to the other party, which in this case is client 2 in a client <-> client communication rather than client <-> server communication. The point is that it happens somewhere out of an attacker's control in a trusted environment. Obviously, the same limitation applies to server-side validation, which is that the file must be validated without triggering a latent exploit within it. That's why it's also important to understand the parsing libraries.