[XML-DEV Mailing List Archive Home] [By Thread] [By Date] [Recent Entries] [Reply To This Message]

RE: Features of XML Languages that Increase Complexity?

  • From: David Lee <dlee@calldei.com>
  • To: Simon St.Laurent <simonstl@simonstl.com>, "xml-dev@l..."<xml-dev@l...>
  • Date: Sun, 14 Apr 2013 18:28:09 +0000

RE:  Features of XML Languages that Increase Complexity?
>>>>
Roger listed some aspects at the beginning of the thread (today, 
7:55am).  If those are the criteria, I don't think XML is ever likely to 
be a good choice - except perhaps for a deliberately chosen subset.
<<<<

Yes I read those. And those are normal things one might put in a data structure reguardless of the markup format.
So I am curious why the statement that one shouldn't use XML ... that is what makes it *more insecure* then other formats ?
Lets ignore things like embedded JavaScript ... 

What *specifically* about XML makes it less secure *intrinsically* ?
Even simple formats like CSV can suffer from DOS attacks (say sending a infinitely long line of text without a field separator ?)

None of the things Rodger mentioned , in my mind, make XML *inherently less secure* then any other data representation modeling the same data.  What about the *format* makes it more prone to attacks ?

Say Recursion (one of the listed items)... 
If recursion was not allowed, but yet someone sent a recusive document ... it would be up to the *processor* not the format,, to protect against infinate recursion (same as its up to the *CSV processor* to prevent a buffer overflow).



----------------------------------------
David A. Lee
dlee@calldei.com
http://www.xmlsh.org






[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index]


PURCHASE STYLUS STUDIO ONLINE TODAY!

Purchasing Stylus Studio from our online shop is Easy, Secure and Value Priced!

Buy Stylus Studio Now

Download The World's Best XML IDE!

Accelerate XML development with our award-winning XML IDE - Download a free trial today!

Don't miss another message! Subscribe to this list today.
Email
First Name
Last Name
Company
Subscribe in XML format
RSS 2.0
Atom 0.3
 

Stylus Studio has published XML-DEV in RSS and ATOM formats, enabling users to easily subcribe to the list from their preferred news reader application.


Stylus Studio Sponsored Links are added links designed to provide related and additional information to the visitors of this website. they were not included by the author in the initial post. To view the content without the Sponsor Links please click here.

Site Map | Privacy Policy | Terms of Use | Trademarks
Free Stylus Studio XML Training:
W3C Member
Stylus Studio® and DataDirect XQuery ™are products from DataDirect Technologies, is a registered trademark of Progress Software Corporation, in the U.S. and other countries. © 2004-2013 All Rights Reserved.