Data files and security

There was an interesting post to the OCAL mailing list about the possibility of embedding malware in an SVG file, and how was it being dealt with. The answer is that it isn’t currently but clearly it needs to be. One of the most interesting aspects is that it can be time sensitive. e.g. A perfectly good piece of clipart could become an advert after it’s been displayed for 5 minutes. This means that the problem does not involve any data outside of the file itself, and cannot be detected from generated thumbnails…. aargh, this’ll be hard to solve.

0 Responses to “Data files and security”


  1. No Comments

Leave a Reply




About

I’m David Illsley, I work in Web Services development at IBM Hursley, which involves work on the Apache WS Project, where I am a committer and PMC member. When not working with technology, I spend a lot of time on the backstage aspects of theatre, and a sadly decreasing amount of time reading.

a

Disclaimer

The postings on this site solely reflect the personal views of the author and do not necessarily represent the views, positions, strategies or opinions of IBM or IBM management.