Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>> font hinting is Turing complete

TIL. But, from the Wikipedia article:

>> Although incapable of receiving input and producing output as normally understood in programming

Great. So this is why this hasn't been the subject of 0-day hacks since like 1988.

Also, about that Orson Wells thing (from the linked paper):

>>In 1938, Orson Welles and his Mercury Theatre on the Air performed an infamous broadcast of War of the Worlds [12]. The broadcast begins with a brief theatri- cal introduction, followed by simulated news broadcasts describing an alien invasion of New Jersey that run for thirty-eight minutes before the first and only intermis- sion, after which the story shifts to the past tense and a fictional tone. Prior to the intermission, there is not one commercial, not one word out of character, and not one scene in the past tense to clue the listener in on the fictional nature of the broadcast. While Welles surely was not concerned with attacking digital radios in 1938, his broadcast does follow the gen- eral pattern of the attacks in this paper. His PIP in this case is the thirty-eight minute panicked broadcast, while the introduction could be considered an outer header. Listeners who miss the introduction might believe the first act to be factual, just as a digital radio which misses a preamble might interpret the PIP to be a legitimate and full packet.

So basically, because every packet protocol has headers and headers can be spoofed, and War of the Worlds was essentially a header spoof, let's call this the Orson Wells attack?

Maybe instead of the Big Scary Iceberg website, we can call it the Leonardo DiCaprio list of bad shit that could happen to you a boat?



Is this phenomenon related to why websockets use masking? I believe it's something to do with shitty proxies being vulnerable to being cache-poisoned when an attacker sends data down the websocket (packet in packet) which looks like HTTP traffic.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: