Skip to content

Comment on OpenZL: An open source format-aware compression frameworkparent

Comments

If the decompressor is included in the compressed file and it's malicious, the file can hardly be called known good.

But also I guess the logic of the decompressor could output different files in different occasions, for example, if it detects a victim, making it difficult to verify.

If it can "detect a victim", then the sandbox is faulty. The decompressor shouldn't see any system details. Only the input and output streams.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.