4 ms·
I think it's funny that removing what looks like actual key material doesn't break a key, but having the wrong kind of newline, or trailing newline in a .pem fi
by locusofself 4y ago
I think it's funny that removing what looks like actual key material doesn't break a key, but having the wrong kind of newline, or trailing newline in a .pem file can cause certain programs (webservers etc) to not be able to load a cert or key.
- ausudhz 4y agoThat's the difference between format and content. Web servers make sure the format is correct, they won't inspect the content
- Dylan16807 4y agoI'm pretty sure they mean a web server configured to use the content for TLS.
- marcosdumay 4y agoIsn't the whitespace in pem files just recommended? AFAIK, it's there just for interoperability with old transport protocols and not a part of the data at all.
- IshKebab 4y agoA good example of the robustness of binary formats compared to text formats.
- metafunctor 4y agoThis has nothing to do with binary versus text.
- myself248 4y agoI think it does, insofaras OSs feel free to just fuck with the contents of files they think are text, replacing newlines willy-nilly. Files not identified as text are safe from such automatic tampering.
- MayeulC 4y agoI've never seen this behaviour at an OS level. This seems like an editor issue, and binary files are not exempt from being messed up by a slightly incompatible editor, far from it.
- nemetroid 4y agoPerhaps you have been spared from writing code for Windows: https://learn.microsoft.com/en-us/cpp/c-runtime-library/reference/fopen-wfopen?view=msvc-170 https://learn.microsoft.com/en-us/cpp/c-runtime-library/refe... > In text mode, carriage return-line feed (CRLF) combinations are translated into single line feed (LF) characters on input, and LF characters are translated to CRLF combinations on output.
- Dylan16807 4y agoIs there a reason I should blame the OS specifically and not the C runtime?
- nemetroid 4y agoI guess it depends on how specific you want to be. The Windows C runtime is a component of the OS.
- Dylan16807 4y agoWell you're not really supposed to use the OS copy of msvcrt.dll
- tedunangst 4y agoYes, library functions do what you ask them to do.
- MayeulC 4y agoIMO that distinction doesn't make much sense. Text is (as soon as it's stored on a computer) a binary format: you have to specify encoding, etc. Inserting or removing a control character in a binary file would break stuff too. Maybe even more so. You may think of the ability to add CRCs (or at least checksums/parity bits) in a binary file? That's extra work, and can be provided by other mechanisms, like par files or at the filesystem level. The advantage of text formats is that binary decoders for text are ubiquitous. That said, it's usually simple to filter input data through a decoder like gzip.
- IshKebab 4y agoYou're not thinking about the human element. Parsers are implemented by real people, and they make mistakes. If a format is human-readable and text based it's both far more likely that a) the spec isn't actually complete (because there's an implicit "sensible" option), and b) people don't read the spec anyway and guess the "sensible" option. There are countless examples of bugs and security flaws in HTTP that wouldn't have been a problem with e.g. Protobuf.
- woodruffw 4y agoI don't think this is a good example of robustness: if the change had happened to affect the DER encoding instead of just a field within the DER encoding, this could just have easily been an example of the fragility of binary formats. Rather, what's happening here is that the interpretation of the parsed format is malleable in an arguably incorrect way. There aren't any great solutions that I'm aware of to that, since the "fix" is to validate the correctness of fields that ultimately don't matter to the operation at hand.