2 ms·
What?!? BREH, read Effective Java on Serialization. Every serialization format has security implications. Some try to make this explicit and probably fail in
by mindless_solips 5y ago
What?!? BREH, read Effective Java on Serialization.
Every serialization format has security implications.
Some try to make this explicit and probably fail in capturing all conceivable holes. Some leave this implicit to give you "fun surprises."
- kevinmgranger 5y agoWhat "fun surprises" does JSON have, aside from "the object could be arbitrarily big" ?
- mindless_solips 5y agoA serialization format is more than just how things are described on the wire. It's also about how both sides are expected to receive and transmit it. Naive processing of JSON in certain situations can run into sharp edges like this: https://rules.sonarsource.com/java/RSPEC-4544 https://rules.sonarsource.com/java/RSPEC-4544 Serialization formats are a part of Protocols, which essentially form the software equivalent of a spoken language between two people. Like words, the bytes can have a general syntax and expected semantic, but still be open to problematic interpretation. Like the conceptual difference between a language like English and Ithkuil. (http://www.newyorker.com/magazine/2012/12/24/utopian-for-beginners http://www.newyorker.com/magazine/2012/12/24/utopian-for-beg...) Like Ithkuil, some formats can specify "a little more" in a way that tries to prescribe semantic meaning and syntax such that implementing according to spec limits the opportunities for issues like this to happen.