Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
spyc
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
spyc
2y ago
There are parsers that only implement a tiny subset of XML. And Expat has compile time flags to disable some of that machinery where not needed. It's arguably no longer XML then though.
32.
▲
by
spyc
2y ago
Thank you!
33.
▲
by
spyc
2y ago
Thanks for sharing that research!
34.
▲
by
spyc
2y ago
"Quickly kill the process" is still a denial of service security problem.
35.
▲
by
spyc
2y ago
Correct.
36.
▲
by
spyc
2y ago
Did you see the article references [1][2] from 2006 and 2017 that already argue that recursion is a security problem? It's not new just not well-known. [1] https://www.researchgate.net/publication/220477862_The_Pow
37.
▲
by
spyc
2y ago
That idea works in general but causes false positives: No artificial limit you pick is "right" and the false positives can be avoided by getting rid of the recursion altogether. PS: It's not one single function, not direct bu
38.
▲
by
spyc
2y ago
The point of termination is beyond stack overflow here, that's the problem. And unlike heap, stack does not tell you gently that it's running out.
39.
▲
Recursion kills: The story behind CVE-2024-8176 in libexpat
(blog.hartwork.org)
162 points
by
spyc
2y ago
|
163 comments
40.
▲
by
spyc
2y ago
Not if you need to report the same thing to multiple parties. And why make it hard to someone who does whitehat work for you.
41.
▲
by
spyc
2y ago
That's not a good reason to not host the file.
42.
▲
by
spyc
2y ago
People who spent hours finding the right security contacts for companies without luck would likely disagree. The key failure is not the single missing file, but that security contacts are too hard to find and the effect that has.
43.
▲
How to help an Open Source project that your company depends on
(blog.hartwork.org)
1 points
by
spyc
2y ago
|
0 comments
44.
▲
Most IT companies fail to serve security.txt for RFC 9116 in 2025
(blog.hartwork.org)
43 points
by
spyc
2y ago
|
32 comments
45.
▲
Expat 2.6.3 released, includes security fixes
(blog.hartwork.org)
2 points
by
spyc
2y ago
|
0 comments
46.
▲
Stop coworkers from adding cyclic imports
(github.com)
3 points
by
spyc
2y ago
|
0 comments
47.
▲
Clone arbitrary single Git commit
(blog.hartwork.org)
3 points
by
spyc
2y ago
|
0 comments
48.
▲
hashin pins Python dependencies to checksums in requirements.txt for security
(github.com)
1 points
by
spyc
2y ago
|
0 comments
49.
▲
Expat 2.6.2 released, includes security fixes
(blog.hartwork.org)
1 points
by
spyc
3y ago
|
0 comments
50.
▲
Ethical challenges in IT security [slides]
(int21.de)
1 points
by
spyc
3y ago
|
0 comments
51.
▲
Expat 2.6.0 released, includes security fixes
(blog.hartwork.org)
3 points
by
spyc
3y ago
|
0 comments
52.
▲
GitHub phishing warning: mails titled "<user> invited you to <repo>"
1 points
by
spyc
3y ago
|
0 comments
53.
▲
Record a chess game live and upload the PGN to Lichess
(github.com)
1 points
by
spyc
3y ago
|
0 comments
54.
▲
by
spyc
3y ago
The way I read https://lore.kernel.org/stable/20231205122122.dfhhoaswsfscuh... 6.5+ should be okay. PS: Please correct me if not!
55.
▲
by
spyc
3y ago
Could you share your source on how/when/if O_DIRECT is required? Have a link?
56.
▲
by
spyc
3y ago
The backing Git repository is at https://github.com/MegaManSec/Squid-Security-Audit
57.
▲
Official GitHub SSH server key fingerprints
(docs.github.com)
2 points
by
spyc
4y ago
|
0 comments
58.
▲
Keeping your GitHub Actions and workflows secure
(securitylab.github.com)
2 points
by
spyc
4y ago
|
0 comments
59.
▲
Geiss source code released under BSD license now
(github.com)
3 points
by
spyc
4y ago
|
0 comments
60.
▲
Sandwine: Sandbox Wine on Linux using bubblewrap
(github.com)
1 points
by
spyc
4y ago
|
0 comments
More ›