wireshark: yet another pile of dissector flaws
wireshark: yet another pile of dissector flaws
Posted Oct 6, 2014 22:32 UTC (Mon) by bronson (guest, #4806)In reply to: wireshark: yet another pile of dissector flaws by raven667
Parent article: wireshark: yet another pile of dissector flaws
> it makes sense to work on infrastructure to limit the amount of damage that can be done by a malfunctioning decoder, by sandboxing or by providing a safe implementation toolkit
Not if you want to ship anything this decade. How many man-hours have been sunk into Chrome's sandboxing? (and they're still working on it). How many resources does Wireshark have compared to Chrome?
I also want my soldering iron hot and my kitchen knives sharp. This means that they must all be used with training and caution. Sure, I would dearly love safer tools but, so far, this is the best that the experts have managed with the resources they had.
And it's really not that bad.
