4 ms·
Interesting idea, but the article greatly downplays the dos angle. Most applications consume fair amount of resources to start up - there are config files to pa
by joemag 8y ago
Interesting idea, but the article greatly downplays the dos angle. Most applications consume fair amount of resources to start up - there are config files to parse, caches to warm, and so on. So there is an imbalance of cost between an attacker, who has to submit another input, and target,who has to restart the process. Hence a great dos angle. Pooling only helps if you can replenish the pool faster than the attacker can drain it.
So if you running a multi-tenant service, where one of the tenants could be a potential adversary, having a crash-bug is enough for a serious denial of service attack.
- moyix 8y agoYep, there are plenty of applications where crashing is a big deal! But, we think, also plenty where that's not an issue. Note also that the "unused" strategy creates bugs that don't cause crashes (but they could be detected with something like ASAN).