3 ms·
Feature are kind of a negative for security. Imagine if yaml was used!
by treve 2y ago
Feature are kind of a negative for security. Imagine if yaml was used!
- alexchamberlain 2y agoI think there is a "safe" subset of both XML and YAML that 80% of people actually use.
- bawolff 2y agoFrom a security perspective that's kind of useless, as your concern is not what the "good" people do, it's what the "bad" people do.
- alexchamberlain 2y agoWell, you can define such a subset and write or configure parsers to only use that; I've seen both XML and YAML libraries do just that, by disabling remote file loading or arbitrary code execution for example.
- bawolff 2y agoDisabling xml remote entities and billion laughs is a given. In the context of saml that's hardly the least of it. Lots of the problems are things like allowing comments to sort of change the meaning of the document, allowing signatures to sign only part of the document. Allowing multiple signatures to sign different parts of the document, etc.
- Muromec 2y agowhich is exactly the problem. if you have two parsers of the same format in a security context that show slightly different behavior (maybe in the rest 20% or maybe not) it's often enough.