←back to thread

312 points campuscodi | 1 comments | | HN request time: 0.215s | source
Show context
oncallthrow ◴[] No.43374582[source]
XML is to authentication bypasses what C is to buffer overflow attacks
replies(4): >>43374583 #>>43374813 #>>43375202 #>>43375808 #
dietr1ch ◴[] No.43374813[source]
Sad that XML has too many features for an otherwise somewhat nice, but verbose markup language.
replies(2): >>43374910 #>>43374941 #
treve ◴[] No.43374910[source]
Feature are kind of a negative for security. Imagine if yaml was used!
replies(1): >>43374958 #
alexchamberlain ◴[] No.43374958[source]
I think there is a "safe" subset of both XML and YAML that 80% of people actually use.
replies(2): >>43374973 #>>43375111 #
1. Muromec ◴[] No.43375111[source]
which is exactly the problem. if you have two parsers of the same format in a security context that show slightly different behavior (maybe in the rest 20% or maybe not) it's often enough.