Skip to content

Comment on Adult sites are stashing exploit code inside svg filesparent

Comments

Not sure I've heard that angle before. I'm tempted to agree, but then the choice of *xml* as the enclosing format argues strongly that efficiency wasn't at the forefront of the design criteria.

Also the dates don't work. HTTP/1.1 with gzip/compress/deflate encodints was live in browsers and servers with inline compression well before the standard was published in RFC 2068 in 1997. SVG's spec was four years behind that, and IIRC adoption being pretty glacial as far as completeness and compliance.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.