Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Useful? Hell, no. Like most technology derived from OSI, it's garbage that has been the source of a huge number of software vulnerabilities.


~98% of the ASN.1 parsing bugs could have been prevented by generating the parser instead of handwriting yet another recursive descent parser "with a few clever optimisations".


But think about that 1us lost. /s


Reminds me of all the Trotskyists who say Communism has never been discredited because no true Communist regime ever existed, only forms of State Capitalism. Why oh why has no actual ASN.1 parser ever hewed to the self-evident Platonic ideal of machine-generated purity?


ASN.1 parser generators exist though...


The question around this is whether vulnerabilities show up because the technology is bad or because it’s widely used, triggers interest by researchers, and a certain amount of any implementations will have their set of issues.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: