Security Risks of Unicode

From: Elliotte Rusty Harold (elharo@metalab.unc.edu)
Date: Sun Jul 16 2000 - 08:27:46 EDT


Bruce Schneier expresses some concerns about "Security Risks of
Unicode" in the latest issue of his Cryptogram newsletter. Thoser who
don't subscribe can see:

http://www.counterpane.com/crypto-gram-0007.html#9

At this point the concerns are mostly theoretical. Nonetheless I
think they're reasonable, especially when you consider the recent
discussions here about C1 control characters and the unintended
consequences of these characters. Throw XML/Unicode encoded
application protocols like SOAP and XML-RPC into the mix and who
knows what can happen? Which is pretty much Schneier's point.

Anyway, I'm curious to know what other Unicodists think about the
potential security implications Schneier raises. I'm not sure if he
subscribes to this list (unicode@unicode.org,
http://www.unicode.org/unicode/consortium/distlist.html) or not so I
cc'd him so he can participate as well.

+-----------------------+------------------------+-------------------+
| Elliotte Rusty Harold | elharo@metalab.unc.edu | Writer/Programmer |
+-----------------------+------------------------+-------------------+
| The XML Bible (IDG Books, 1999) |
| http://metalab.unc.edu/xml/books/bible/ |
| http://www.amazon.com/exec/obidos/ISBN=0764532367/cafeaulaitA/ |
+----------------------------------+---------------------------------+
| Read Cafe au Lait for Java news: http://metalab.unc.edu/javafaq/ |
| Read Cafe con Leche for XML news: http://metalab.unc.edu/xml/ |
+----------------------------------+---------------------------------+



This archive was generated by hypermail 2.1.2 : Tue Jul 10 2001 - 17:21:05 EDT