Re: EXIF support in PNG - MAJOR security issue

"Adeluc" <png-8CwYj0sA/[email protected]>
Newsgroups gmane.comp.graphics.png.general
Organization Adeluc
Message-ID <1CFB6C6BA7F84E4AA68BCBAC99488A30@HPP72600MHZ>
First I want to say I really enjoy reading you guys.  It is refreshing
for me to see smart people working and thinking together.

You all put a lot of time fine tuning this eXIf chunk proposal.
Almost anything that can promote the use of PNG I vote Yes.

As a perfectionist I did not really like the redundancy of information or
the out of sync information in the eXIf chunk after the image as been
modified.

But as someone said, the remaining good information worth it.
And I agree with that.  After all, some out of sync information will
not crash anything and the pertinent information is still available.

Then someone found that eXIf may contain thumbnail and preview
images.  At first I though what kind of damage an out of sync
preview image can do?  Someone seeing the bad preview may delete
the file thinking it is an old version.  That's probably the worst scenario.

Then someone bring the security issue and none of us seem to realize
how much critical it is actually.  For me it is the words "lawyer" and
"boobs" that started me thinking.

If, (and only if) the eXIf chunk may actually contain a preview image clear
enough to be able to identify information present in the original image,
it must definitely NOT be safe to copy.  (You should even create a new
bit indicating DANGEROUS to copy for such a chunk.)

We are all nice guys trying to make this world a better place and
thinking evil is definitely not natural for any of us unless software
security is our job.

Here is a very simple example:
Someone takes a picture of its credit card bill, loads it in a paint 
program,
black out all the very personal information, and saves the picture as PNG
because it is a more suitable format for such picture.  He is now 100%
sure that the picture is safe to be published on its blog for what so ever
reason.  Evil persons will know about eXIf because it is their job to know
about such vulnerability.  You are all smart, you know what happens next.

The last thing we want to see on the news are the words "PNG file format"
associated with "major security issue", "hidden information", "spying",
"they knew it and they voted for it!"  =)

If your future goal is to destroy PNG in favor to Google WebP your are
definitely on the good path to achieve that.


I hope I have totally misunderstood the security issue here and if it is the
case, then I apologize for this very long post.

Keep the good work and have fun doing it.


  _______
/ Adeluc /
¯¯¯¯¯¯¯¯¯¯



------------------------------------------------------------------------------
Developer Access Program for Intel Xeon Phi Processors
Access to Intel Xeon Phi processor-based developer platforms.
With one year of Intel Parallel Studio XE.
Training and support from Colfax.
Order your platform today. http://sdm.link/xeonphi
_______________________________________________
png-mng-misc mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/png-mng-misc
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.