4 ms·
Again, there are safe ways of doing this. For example, Wuffs exists: https://github.com/google/wuffs https://github.com/google/wuffs At the very least, big mon
by lambdaone 2y ago
Again, there are safe ways of doing this. For example, Wuffs exists: https://github.com/google/wuffs https://github.com/google/wuffs
At the very least, big money security software companies should be parsing untrusted content with some kind of rigorouly safe approach, not just squirting it through a big pile of C/C++.
And don't get me started on the whole concept of undefined behavior in those languages. To quote I. I. Rabi, "Who ordered that?"
- gruez 2y ago>At the very least, big money security software companies should be parsing untrusted content with some kind of rigorouly safe approach the malformed files were updates from crowdstrike itself. It's not exactly "untrusted content".
- kchr 2y agoIt is untrusted data in the sense of files being read from disk that are not part of the signed kernel driver code.
- gruez 2y agoThe files in question reside within C:\windows, which requires admin privileges to write to. If untrusted data can end up there, you're already on the other side of the airtight hatchway[1]. [1] https://devblogs.microsoft.com/oldnewthing/20220907-00/?p=107132 https://devblogs.microsoft.com/oldnewthing/20220907-00/?p=10...