← Back to team overview

ubuntu-phone team mailing list archive

Re: DocViewer && HTML

 

On Mon, Nov 9, 2015 at 8:03 PM, Matthias Apitz <guru@xxxxxxxxxxx> wrote:

> El día Monday, November 09, 2015 a las 07:47:48PM +0000, Andrea Bernabei
> escribió:
>
> > Sorry, I'm a bit skeptic whenever I read that one file can be passed off
> as
> > another fileformat without that being explicitly allowed :)
> > I wouldn't be surprised to hear that this "feature" could be a security
> > risk :D (is that html engine reliable?)
> >
> > Or maybe I'm just being overly paranoid ;)
>
> To which application you want to pass a file named 'matthias' or a file
> named 'andrea'? A file appendix of 'foo.xyz' will never say something
> reliable about the content of it.
>

I didn't mean to imply reading the extension is a reliable way of
identifying a file ;)


>
>         matthias
>
> --
> Matthias Apitz, ✉ guru@xxxxxxxxxxx, 🌐 http://www.unixarea.de/  ☎
> +49-176-38902045
> «(über die DDR)... Und allein dieser Mangel (an Sozialismus) und nichts
> anderes führte zum Tod.
> Und wer da nicht trauert, hat kein Herz, und wer da nicht neu anpackt, hat
> auch keins verdient.»
> «(sobre la RDA)... Y solo esta escasez (de socialismo) y no otra cosa, le
> llevó a la muerte.
> Y quien no está de luto, no tiene corazón, y quien no se lanza a luchar de
> nuevo, no se merece
> corazón.», junge Welt del 3 de octubre 2015, p. 11
>

References