7 ms·
That critique adresses security aspects.
by jnxx 2y ago
That critique adresses security aspects.
- shzhdbi09gv8ioi 2y agoYou seem to be rather determined in continuing to badmouth Lasse, ignoring me and others questioning your motives. Here are recent examples: 1. https://news.ycombinator.com/item?id=39872919 https://news.ycombinator.com/item?id=39872919 2. https://news.ycombinator.com/item?id=39873552 https://news.ycombinator.com/item?id=39873552 3. https://news.ycombinator.com/item?id=39873133 https://news.ycombinator.com/item?id=39873133 4. https://news.ycombinator.com/item?id=39872770 https://news.ycombinator.com/item?id=39872770
- showdeadplease 2y ago[dead]
- Matl 2y agoThere may be some suboptimal things about security of the XZ file format, I don't know. I bet you there are less than optimal security choices in your most cherished piece of software as well. This thread is about an exploit that does not rely on any potential security problems in the DESIGN of the xz FORMAT. Therefore your point, even if valid as a general one, is not really relevant to the exploit we're discussing. Further, there's some proof needed that any potential suboptimal aspects of the security design of the xz FORMAT was designed such so that it could be exploited later or simply because no programmer is an expert on every aspect of security ever. I mean you could be the most security conscious programmer and your chain could still be compromised. Security today is such a vast field and it takes so little to get you compromised that proclaiming anything 'secure design' these days is practically impossible. I bet you an audit of lzip would find plenty of security issues, would those be intentional?