Comment on Language-theoretic SecurityComments−vezzy-fnord10yA paper earlier this year at Usenix entitled "The Bugs We Have to Kill" takes a similar position: https://www.usenix.org/system/files/login/articles/login_aug...In fact, djb quite famously identified parsing as one of the major sources of vulnerabilities, hence his devotion to formats like TAI64, netstrings, cdb and use of the file system namespace where sufficient.(See #5: http://cr.yp.to/qmail/guarantee.html)−samuirai10yThe usenix paper you linked is from the langsec people
Comments
A paper earlier this year at Usenix entitled "The Bugs We Have to Kill" takes a similar position: https://www.usenix.org/system/files/login/articles/login_aug...
In fact, djb quite famously identified parsing as one of the major sources of vulnerabilities, hence his devotion to formats like TAI64, netstrings, cdb and use of the file system namespace where sufficient.
(See #5: http://cr.yp.to/qmail/guarantee.html)
The usenix paper you linked is from the langsec people