4 ms·
There always been an issue here with files reporting to be one thing but being another. Trusting the file extension is amateur to say the least. ‘Magic string
by junto 2y ago
There always been an issue here with files reporting to be one thing but being another.
Trusting the file extension is amateur to say the least.
‘Magic strings’ in the header of the file is the usual way, but even then, you can’t really trust it.
What we really need is some way to guarantee that the contents are in a valid format as defined by the header, and haven’t been tampered with and signed as such, and embeds that in the file itself. Then I can take the contents of the file after the header, hash it and compare it with the embedded sig.
Back porting this to standard formats though would be a nightmare.
- klabb3 2y agoSo an attacker should sign their malicious webp or jpeg files beforehand? That doesn’t help at all. No, I agree very much with parent here. I think compile time safety and rust fanatism has been oversold, but let’s face it this is the perfect use case, a match made in heaven. Decoding in C/C++ has a Dunning Kruger deceitful appeal. People think they can do it, but time and time again, we find critical holes, even when written by 10x wizard Nobel laureate engineers. At the same time, decoding needs to be crazy performant. So, this is the moment to shine for languages like Rust. I am 100% in support of this.