Skip to content

Comment on OpenSSL Security Advisory: TLS heartbeat read overrunparent

Comments

"Don't roll your own parsers" should really be up there with "Don't roll your own crypto".

.. and if you do, don't do it in a highly memory-unsafe language. Espcially when it's for a security critical piece of central internet infrastructure!

How do the Ruby-YAML and Python-Pickle vulnerabilities get cataloged?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.