Re: Is MathML really Dangerous?
Paul Libbrecht <[email protected]> Fri, 04 Dec 2015 23:04:56 +0100
| Newsgroups | gmane.comp.web.mathematics |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format.
--------------090202090804080604040503
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit
Moritz,
Can an answer be read from the Media-Type registration's "Security
Concerns":
http://www.w3.org/TR/MathML3/appendixb.html
>From there, one can probably read what can be removed to make MathML safe:
- remove anything that includes external content (e.g. DTD things,
styles, images, annotations),
- do not compute with it (or remove MathML-Content),
- remove foreign content (anything outside the MathML namespace and
probably all annotations).
This has been validated by readers of the ietf-media-type mailing-list,
I believe.
I'll note that the same requirement has been expressed for MathML to be
considered by the ClipOps spec https://w3c.github.io/clipboard-apis/
which is still in draft.
Are we not able to write a note that demonstrates such a security?
Paul
> Physikerwelt <mailto:[email protected]>
> 4 décembre 2015 19:04
> Dear W3C Math WG,
>
> I wonder if there is a resilient security assessment for MathML. It
> would be nice, if there was at least a subset of MathML, for which the
> security was proven according to state-of-the-art of science and
> technology. For example I could imagine that only presentation MathML
> without a finite list of possible dangerous elements such as maction
> or annotation could be the secure MathML subset.
>
> The background of my question is that the Wikimedia Foundation
> considers opening the POST endpoint for converting several input
> formats (i.e. TeX, AsciMathML, and MathML) to MathML + SVG (+ PNG) [1]
> for the public[2].
> Currently this conversion endpoint it is only accessible from within
> the Wikimedia Foundation cluster and only accepts texvc* input.
>
> Best
>
> Moritz Schubotz
>
> [1]
> https://en.wikipedia.org/api/rest_v1/?doc#!/Math/post_media_math_check_type
> if you try this link you’ll get a “This client is not allowed to use
> the endpoint” exception rather than the security checked texvc output
> you receive in the unstable demo here
> http://math.beta.wmflabs.org:7231/math.beta.wmflabs.org/v1/?doc#!/Math/post_media_math_check_type
>
> [2] https://phabricator.wikimedia.org/T116147
>
> *) texvc is a well-defined subset of LaTeX with some custom macros.
>
--------------090202090804080604040503
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: 8bit
<html><head>
<meta content="text/html; charset=UTF-8" http-equiv="Content-Type">
</head><body bgcolor="#FFFFFF" text="#000000">Moritz,<br>
<br>
Can an answer be read from the Media-Type registration's "Security
Concerns":<br>
<a class="moz-txt-link-freetext" href="http://www.w3.org/TR/MathML3/appendixb.html">http://www.w3.org/TR/MathML3/appendixb.html</a><br>
<br>
>From there, one can probably read what can be removed to make MathML
safe:<br>
- remove anything that includes external content (e.g. DTD things,
styles, images, annotations),<br>
- do not compute with it (or remove MathML-Content),<br>
- remove foreign content (anything outside the MathML namespace and
probably all annotations).<br>
<br>
This has been validated by readers of the ietf-media-type mailing-list, I
believe.<br>
<br>
I'll note that the same requirement has been expressed for MathML to be
considered by the ClipOps spec <a class="moz-txt-link-freetext" href="https://w3c.github.io/clipboard-apis/">https://w3c.github.io/clipboard-apis/</a>
which is still in draft.<br>
<span>
</span><br>
Are we not able to write a note that demonstrates such a security?<br>
<br>
Paul<br>
<blockquote style="border: 0px none;"
cite="mid:CA+fbXr3iz_5GKxtYgg5hFmkQ-2tW2m2hGQL3_gGhMJVNMiQT2Q@mail.gmail.com"
type="cite">
<div style="margin:30px 25px 10px 25px;" class="__pbConvHr"><div
style="width:100%;border-top:1px solid #EDEEF0;padding-top:5px"> <div
style="display:inline-block;white-space:nowrap;vertical-align:middle;width:49%;">
<a moz-do-not-send="true" href="mailto:[email protected]"
style="color:#737F92
!important;padding-right:6px;font-weight:bold;text-decoration:none
!important;">Physikerwelt</a></div> <div
style="display:inline-block;white-space:nowrap;vertical-align:middle;width:48%;text-align:
right;"> <font color="#9FA2A5"><span style="padding-left:6px">4
décembre 2015 19:04</span></font></div> </div></div>
<div style="color:#888888;margin-left:24px;margin-right:24px;"
__pbrmquotes="true" class="__pbConvBody"><div>Dear W3C Math WG,<br><br>I
wonder if there is a resilient security assessment for MathML. It<br>would
be nice, if there was at least a subset of MathML, for which the<br>security
was proven according to state-of-the-art of science and<br>technology.
For example I could imagine that only presentation MathML<br>without a
finite list of possible dangerous elements such as maction<br>or
annotation could be the secure MathML subset.<br><br>The background of
my question is that the Wikimedia Foundation<br>considers opening the
POST endpoint for converting several input<br>formats (i.e. TeX,
AsciMathML, and MathML) to MathML + SVG (+ PNG) [1]<br>for the
public[2].<br>Currently this conversion endpoint it is only accessible
from within<br>the Wikimedia Foundation cluster and only accepts texvc*
input.<br><br>Best<br><br>Moritz Schubotz<br><br>[1]
<a class="moz-txt-link-freetext" href="https://en.wikipedia.org/api/rest_v1/?doc#!/Math/post_media_math_check_type">https://en.wikipedia.org/api/rest_v1/?doc#!/Math/post_media_math_check_type</a><br>if
you try this link you’ll get a “This client is not allowed to use<br>the
endpoint” exception rather than the security checked texvc output<br>you
receive in the unstable demo here<br><a class="moz-txt-link-freetext" href="http://math.beta.wmflabs.org:7231/math.beta.wmflabs.org/v1/?doc#!/Math/post_media_math_check_type">http://math.beta.wmflabs.org:7231/math.beta.wmflabs.org/v1/?doc#!/Math/post_media_math_check_type</a><br><br>[2]
<a class="moz-txt-link-freetext" href="https://phabricator.wikimedia.org/T116147">https://phabricator.wikimedia.org/T116147</a><br><br>*) texvc is a
well-defined subset of LaTeX with some custom macros.<br><br></div></div>
</blockquote>
<br>
</body></html>
--------------090202090804080604040503--