[XML-DEV Mailing List Archive Home] [By Thread] [By Date] [Recent Entries] [Reply To This Message]

Re: Illustrating the Risk of Unconstrained Strings

  • From: David Carlisle <d.p.carlisle@gmail.com>
  • To: "Costello, Roger L." <costello@mitre.org>
  • Date: Sat, 7 Nov 2015 13:19:59 +0000

Re:  Illustrating the Risk of Unconstrained Strings
On 7 November 2015 at 12:46, Costello, Roger L. <costello@mitre.org> wrote:
> Hi Folks,
>
> A colleague and I created a graphic which illustrates the risk of unconstrained strings:
>
> http://www.xfront.com/Illustrating-the-Risk-of-Unconstrained-Strings.pdf
>
> /Roger
>
> __

Sadly like many graphics purporting to illustrate some mathematical
data, it doesn't illustrate anything.
There is no definition of the values used, and no units on the
diagram, so it is just a quarter circle
randomly coloured with no information content.

The first sentence isn't clearly true (the terms are undefined so it
is hard to be sure).
But the way to prevent a string containing malicious content is to control
write access to it.

If I have a string of length 1 constrained to be "0" or "1" that is
somewhere in the green section of
your picture, I assume. But if it is 1=nuclear destruction 0=do
nothing, then it has a 50%
chance of having malicious content if there are no  controls over what
is writing to it.
If 50% is green what percentages do red represent?

David


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index]


PURCHASE STYLUS STUDIO ONLINE TODAY!

Purchasing Stylus Studio from our online shop is Easy, Secure and Value Priced!

Buy Stylus Studio Now

Download The World's Best XML IDE!

Accelerate XML development with our award-winning XML IDE - Download a free trial today!

Don't miss another message! Subscribe to this list today.
Email
First Name
Last Name
Company
Subscribe in XML format
RSS 2.0
Atom 0.3
 

Stylus Studio has published XML-DEV in RSS and ATOM formats, enabling users to easily subcribe to the list from their preferred news reader application.


Stylus Studio Sponsored Links are added links designed to provide related and additional information to the visitors of this website. they were not included by the author in the initial post. To view the content without the Sponsor Links please click here.

Site Map | Privacy Policy | Terms of Use | Trademarks
Free Stylus Studio XML Training:
W3C Member
Stylus Studio® and DataDirect XQuery ™are products from DataDirect Technologies, is a registered trademark of Progress Software Corporation, in the U.S. and other countries. © 2004-2013 All Rights Reserved.