Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
d@nny disc@ mc²
d@nny disc@ mc²
@hipsterelectron@circumstances.run  ·  activity timestamp 3 hours ago

cloudflare is such a meme https://blog.cloudflare.com/a-solution-to-compression-oracles-on-the-web/

like they start off by saying yeah we got this phd on the case of security. we have a proof of concept that does not do the horribly fucked up thing http makes you do

The Cloudflare Blog

A Solution to Compression Oracles on the Web

Compression is often considered an essential tool when reducing the bandwidth usage of internet services. The impact that the use of such compression schemes can have on security, however, has often been overlooked.
  • Copy link
  • Flag this post
  • Block
d@nny disc@ mc²
d@nny disc@ mc²
@hipsterelectron@circumstances.run replied  ·  activity timestamp 3 hours ago

then there's just this perfect couple of sentences in a row

We decided to use selective compression, compressing only non-secret parts of a page, in order to stop the extraction of secret information from a page.

fucking genius. turing award right here

We found that in most cases a secret within a webpage can be described in terms of a classical regular expression.

so you wrote a regex

to identify secret info

....

These descriptions allow us to identify secrets online as a response is streamed.

also a normal thing for someone to say

  • Copy link
  • Flag this comment
  • Block
Bredroll
Bredroll
@Bredroll@mas.to replied  ·  activity timestamp 3 hours ago

@hipsterelectron now i want to read about New Age Regex!

  • Copy link
  • Flag this comment
  • Block
d@nny disc@ mc²
d@nny disc@ mc²
@hipsterelectron@circumstances.run replied  ·  activity timestamp 3 hours ago

@Bredroll i have it for you but we need to move past the deeply limiting finite automaton model

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.22 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct