There was an interesting post to the OCAL mailing list about the possibility of embedding malware in an SVG file, and how was it being dealt with. The answer is that it isn’t currently but clearly it needs to be. One of the most interesting aspects is that it can be time sensitive. e.g. A perfectly good piece of clipart could become an advert after it’s been displayed for 5 minutes. This means that the problem does not involve any data outside of the file itself, and cannot be detected from generated thumbnails…. aargh, this’ll be hard to solve.
Advertisement

0 Responses to “Data files and security”