6 ms·
I am not sure if parsing XML is better than parsing JSON. Many languages or libraries' XML parser are dangerous by default. You usually need to manually configu
by maple3142 5y ago
I am not sure if parsing XML is better than parsing JSON. Many languages or libraries' XML parser are dangerous by default. You usually need to manually configure your XML parser to be secure from XML-related attacks. Fortunately, some languages and libraries are going to make XML have a securer defaults, this is a good change. IMO, I think XML shouldn't have include many questionable features from security perspective.
- Sohcahtoa82 5y ago> Many languages or libraries' XML parser are dangerous by default. Seriously, XML External Entities is an incredibly dumb feature. To have it enabled by default makes it even worse.
- pdimitar 5y agoAgreed, and I like the libraries I saw in the past that deliberately only support a small subset of all XML extensions (sadly now I can't remember the names). Reducing attack surface and increasing sanity in one stroke is a policy that much more open-source software has to adopt.
- ievans 5y agoFor those unfamiliar with these attack vectors, there code injection and denial-of-service issues that in previous version of Python, were exploitable by default. Projects like https://pypi.org/project/defusedxml/ https://pypi.org/project/defusedxml/ were designed to be secure against these issues by default, rather than requiring the library user to opt in. The defusedxml project has an excellent matrix showing viability of the attack types against various python XML implementations: https://pypi.org/project/defusedxml/#python-xml-libraries https://pypi.org/project/defusedxml/#python-xml-libraries
- makeitdouble 5y agoYou are right, and XML parsers can have a very large attack surface due to the sheer amount of specs to adhere to. I see XML as better in the expressiveness it has, and more mature out of the box options to validate and transform it. Security and bugs remain an issue, but at the scale it can be used, there is a fighting chance to have experts dealing with the hardening of it all. Swagger like format definitions are still pretty lax in my option in comparison. Now I wouldn't want to get back to XML land, I just think it occupies a pretty solid niche that is hard to match with anything more simple.
- tannhaeuser 5y agoTo be fair, XML wasn't intended as a data exchange format but as simplified SGML subset for use as delivery format on the web. While that largely hasn't happened, XML with XSD (sans rarely used feats) remains a strong exchange format for coarsely-grained inter-party traffic such as payment systems, taxes and other public/private data, etc. I'm guessing the security deficits you mention are XML entity attacks. Well, SGML has CAPACITY ENTLVL in the SGML declaration to limit expansion depth. And a markup authoring or delivery format without entities/text macros is quite useless, even though HTML, when seen as a stand-alone markup language rather than SGML vocabulary, lacks it.
- goodpoint 5y ago> XML wasn't intended as a data exchange format but as simplified SGML subset for use as delivery format on the web You cannot deliver web content without... exchanging data. And you cannot trust servers not to attack browsers.
- HWR_14 5y ago> And you cannot trust servers not to attack browsers. Interesting. I normally see it expressed the other way (trusting the server and not the client). Obviously, both are important.
- mcv 5y agoI guess trust needs to be a two-way street. Even between computers.
- HWR_14 5y agoOr lack-of-trust. Sanitize your inputs, because the other side is always an evil actor.
- josefx 5y agoThere was a time when every browser hack made headlines, now it has to involve something big like specter to get even noticed. Browsers and browser based applications still feature heavily at Pwn2Own style competitions, but YOLO lets add more pointless features with bug ridden APIs with every browser update.