Re: The security of deflate-compressed streams with uncompressed-length field

Willem van Schaik <[email protected]>
Newsgroups gmane.comp.graphics.png.general
Message-ID <[email protected]>
hi Cosmin,

I do hear you (as quoted below) "some people have been able to implement 
correctly", which means to me that many have not been able to do that

so it seems there are some none trivial issues here to implement zTXt or 
zXIf correctly

then why are you so argumentative that we need a compressed version of 
eXIf ?

1) it does give all the dangers of the bad security exploits that you 
and John are both aware of and therefore discussing, but that you think 
could be avoided by someone who knows what he/she is doing ... IMHO if 
that danger is lurking, some hacker in Russia or China will find a way 
around it

2) given a realistic multi-MB camera image file that the camera owner 
otherwise would have stored RAW, but is ok with lossless PNG, then 
adding couple of kB because of a non-compressed EXIF chunk doesn't 
matter a dime

3) nobody seems to be using zTXt (zero out of twelve-hundred), so why 
would anybody now suddenly use zXIf ... all serious decoder programmers 
would have to embark on it, while nobody will use it

trying to remember, I don't think you've ever really contributed 
anything to the PNG spec ... you've either made proposals that nobody 
liked, or you've obstructed proposals of other people ... can't remember 
anything constructive

seems we're now here again !!

Willem



On 2017-02-05 13:19, Cosmin Truta wrote:

>
> Implementors have been able to understand and implement zTXt and iCCP;
> or if not, that meaning and that understanding would have (should
> have) been required.
>

-- 
Willem van Schaik
[email protected]

------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, SlashDot.org! http://sdm.link/slashdot
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.