[XML-DEV Mailing List Archive Home] [By Thread] [By Date] [Recent Entries] [Reply To This Message]

Re: Illustrating the Risk of Unconstrained Strings

  • From: Liam Quin <liam@w3.org>
  • To: "Costello, Roger L." <costello@mitre.org>
  • Date: Sat, 07 Nov 2015 15:39:52 -0500

Re:  Illustrating the Risk of Unconstrained Strings
On 2015-11-07 07:46, Costello, Roger L. wrote:
Hi Folks,

A colleague and I created a graphic which illustrates the risk of
unconstrained strings:

http://www.xfront.com/Illustrating-the-Risk-of-Unconstrained-Strings.pdf
Any such claims need to be based on clear surveys of actual data.
My experience has been that fixed-length buffers in C programs are
symptomatic of less robust programming. Buffer overflow attacks succeed
based on an attempt to put too much data into the space allocated.

Size of character set may increase opportunities for visual glyph puns,
where two different character sequence display sufficiently similarly to
confuse humans. Mathematically, however, a 16-bit-long string has the
same value space regardless of whether it's composed from a single 16-bit
value or from two 8-bit values.

Finally, what evidence did you use to determine the shape of your curve?
Visualizations are useful if they uncover new relationships - if they
allow us to make predictions or increase understanding. Are you suggesting
a polynomial relation between character set, string length and security? Why?

--
Liam Quin, W3C
XML Activity Lead;
Digital publishing; HTML Accessibility


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index]


PURCHASE STYLUS STUDIO ONLINE TODAY!

Purchasing Stylus Studio from our online shop is Easy, Secure and Value Priced!

Buy Stylus Studio Now

Download The World's Best XML IDE!

Accelerate XML development with our award-winning XML IDE - Download a free trial today!

Don't miss another message! Subscribe to this list today.
Email
First Name
Last Name
Company
Subscribe in XML format
RSS 2.0
Atom 0.3
 

Stylus Studio has published XML-DEV in RSS and ATOM formats, enabling users to easily subcribe to the list from their preferred news reader application.


Stylus Studio Sponsored Links are added links designed to provide related and additional information to the visitors of this website. they were not included by the author in the initial post. To view the content without the Sponsor Links please click here.

Site Map | Privacy Policy | Terms of Use | Trademarks
Free Stylus Studio XML Training:
W3C Member
Stylus Studio® and DataDirect XQuery ™are products from DataDirect Technologies, is a registered trademark of Progress Software Corporation, in the U.S. and other countries. © 2004-2013 All Rights Reserved.