3 ms·
> "Rather than exploit an existing vulnerability in the fqzcomp program, as real-world hackers do, they modified the program's open-source code to insert their
by maxton 9y ago
> "Rather than exploit an existing vulnerability in the fqzcomp program, as real-world hackers do, they modified the program's open-source code to insert their own flaw allowing the buffer overflow."
So really, this is not as interesting as the headline would have you believe. Storing data in DNA is nothing new, and these researchers are just using it as input to a program that was deliberately written to improperly handle that data.
- FullMtlAlcoholc 9y agoThe concept itself is interesting in its own right and this is still a very innovative proof of concept that combines techniques from biochemistry and computer security. One of the interesting insights to come out of this is that to ensure a higher probability that the sequencer reads the code correctly, it should be a palindrome.
- omarforgotpwd 9y agoWhats interesting is just the idea that you should sanitize ALL inputs, no matter how unlikely it is that the input could be malicious.
- taeric 9y agoThough, really, is that interesting? Yes, you should treat all input data as data no matter where it came from. And you should have checks in place to reject any data that is out of size/whatever constraints for your software. And for the love of secure software, never blindly execute code from a serialized source without damned good reasons for thinking that source is safe.
- icelancer 9y ago>Though, really, is that interesting? Yes. Trusting human DNA is something that WILL absolutely, 100%, no-doubt-about it happen in the future and you will hear about it. People are good at finding ways to screw things up.
- taeric 9y agoSorry, the interesting like there was supposed to refer to the advice of always sanitize inputs. That, by itself is interesting. Exploring ways it can hurt you in DNA? Yeah, fun thought experiment.
- yoz-y 9y agoI remember that perl has (had?) a feature where all variables would be "tainted". Using a tainted variable would make the program exit in an error and the only way to clean them is to pass them through a regex.
- viraptor 9y agoTainted is a terribly flawed concept unfortunately. At least the way it's implemented normally. Strings are never universally tainted. They're tainted for a specific purpose. One language will treat backticks as a string quote, another as a subshell substitution. One will think $ is ok, another will interpolate the string. But in most cases I've seen, tainted flag is just used for "Ah, we quoted the ' in the string - you're safe now" :-(
- throwaway91111 9y agoI'm not sure exactly what you were expecting, but the title seems suitable to me.