Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

I feel the same. So so so many "regular expression denial-of-service" issues at my last job that just didn't seem serious or often reachable.


I keep getting things like "denial of service when the SCSS or whatever parse is given malicious input”. Great, that's part of the build chain, all of its inputs are stuff we control. Why do we care.


All of my services are internal, yet I am continually getting red alerts that there is a novel denial-of-service that needs to be patched immediately.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: