Same, I'm really wondering why this talk just got 415 likes.. Tbh, this was one of the best talks I ever saw ..
@hikingpete13 жыл бұрын
Thank you. This has really opened my eyes. I'll never look at a parser the same way again.
@dustinronin32623 жыл бұрын
Sorry to be off topic but does any of you know of a trick to get back into an Instagram account..? I was stupid lost the account password. I would love any assistance you can give me.
@kierancain80163 жыл бұрын
@Dustin Ronin Instablaster =)
@VaShthestampede22 жыл бұрын
@@dustinronin3262 Yeah. Change the password.
@il26264 жыл бұрын
who else here from live overflow xD
@amirhoseini356311 ай бұрын
me
@ecostaСағат бұрын
19:32 "If you are into that kind of type theory" - where do I sign?
@jsmuskrat9 ай бұрын
This is a fantastic talk. ( I heard it when it came out and couldn't find it again until recently.)
@aromanstuff13 жыл бұрын
Totally phenomenal talk. The presenter is awesome.
@richtourist10 ай бұрын
I can't quite see the problem with length fields. Suppose the sender wants to send 42 and 69 bytes of arbitrary data: Using delimiters they have to escape any bytes that look like delimiters; and any that look like escapes..? or use something like Rust's r## technique. Using length fields the first byte is how many length fields, then the length fields, which describe the data fields that follow in order. What's the problem? Or are they talking about streams which can't have prior knowledge of their field lengths?
@jjones78373 жыл бұрын
RIP Len.
@KurtisRainboltGreene12 жыл бұрын
S-expressions don't need to use brackets. She specifically suggests using wrapping characters *that wont exist in the sub-language of the value*.
@sydnius13 жыл бұрын
Superb talk. Spot on.
@capability-snob3 ай бұрын
6:25 not capabilities issues? Just lost my coffee! 2012 may have been before many of the Java deserialisation issues that plagued the decade, but 8 of the OWASP top 10 that year are capabilities issues, that is, they go away or become obvious the moment you phrase them in ocap terms. Not that parsing isn't a deeply interesting field, but it seems a stretch to speak of it as the most foundational security discipline.
@MaestroAlvis13 жыл бұрын
@Shorttail Did I miss an MLP reference?
@tcsiwula5 жыл бұрын
break all the things for all the things are broken
@MasonTVTheOG4 жыл бұрын
Glad I’m learning rust
@vytemagic11 жыл бұрын
i came here about being insecure in public.
@t9h3m4 жыл бұрын
Did anyone catch what was going on with the lab coat in the end? I can't really make out anything :)
@maverickwoo2 жыл бұрын
I think it is en.wikipedia.org/wiki/Len_Sassaman#/media/File:LenSassaman-Bitcoin-Tribute.png from the speech.
@samposyreeni13 жыл бұрын
Uhm, a fixed width length field most certainly does not make a protocol context sensitive, but only blows up the (D)FA needed to recognize it. On the other hand I'm reasonably sure context sensitive grammars won't cut something like Elias codes. Otherwise, Patterson's ideas are a beautiful formalization of what I've been saying for the longest time: validate first, then compute with minimal checks. Kudos!
@MasonTVTheOG4 жыл бұрын
No cap rustlang mitigates a lot of this... hell yeah
@Jibes13 жыл бұрын
Link to the blackhat conference talk full of lulz is where?
@slimjim15208 жыл бұрын
Anyone else here because they wanted extra credit for Dr. Winter's class?
@Shorttail13 жыл бұрын
This is fucking awesome. Rainbow Dash agrees.
@Lethn13 жыл бұрын
@GIMBLUTAXT LOL Me too!
@sTL45oUw13 жыл бұрын
"Blackhat 2010 Exploiting the forest with trees" Same BS talk just from last year and at blackhat Who let this academic talk at a hacker con ? She doesn't get it