Re: length restrictions on IDN label

Paul Hoffman / IMC <[email protected]>
Newsgroups gmane.ietf.idn
Message-ID <p05200a0cb9d079021a31@[165.227.249.18]>
At 10:10 PM +0900 10/14/02, Soobok Lee wrote:
>Most applications programmer have been reserving 256 bytes for any LDH
>FQDN buffer space .

It is amazingly arrogant for anyone to make statements about "most 
applications programmer".

>But that convention should be changed to cover the cases of long utf8
>IDN FQDN which may be
>3 or 4 times longer than 256 octets.

Why just UTF8? Why not UTF16? Or GB? Or ... ?

>If this warning is neglected by application programmers,
>some remote malicious crackers will send to users' applications long ACE
>IDNs manufactured to
>cause buffer overflow errors when toUnicoded and seaze control of the
>machine.

Oh, come on. Step 6 of ToUnicode is exactly two words long. Which one 
of those two words do you think that other applications programmers 
will not understand?

--Paul Hoffman, Director
--Internet Mail Consortium
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.