28
you are viewing a single comment's thread
view the rest of the comments
[-] waltersf@bookwyr.me 0 points 5 days ago

cc @modem_down@thebrainbin.org
or, binary signatures, [which I prefer: compressionable], as textfiles are insecure formats.

I prefer a headed, mided, and tailed verification, similar to MPEG keyframing, for constant stream verification.

[-] lurch@sh.itjust.works 1 points 5 days ago

idk about the specific formats, but i don't think you can say that in general. what are those two formats and why does it make a difference in this case?

[-] waltersf@bookwyr.me 1 points 5 days ago
  1. what binary signatures offer:
  • smaller sizes
  • ability to compression
  • the actually signature
  • confidentiality
  1. File headers^def^, miding^def^, tailing^def^.

  2. why textfiles are insecure

i don’t think you can say that in general

What is your academic literacy please?Cite your papers please.

or gen z:
Drop your academic flex.
What grade you at?
papers pls🙏

orly

[-] lurch@sh.itjust.works 1 points 4 days ago

no, i mean, you say text files are insecure and you prefer binary.

while it is true that processing text files needs additional code (validating/converting charsets/encoding), which increases the number of potential attack vectors, security threats introduced by this are not a fault of them being text, but of the parser code.

at the end of the day the attacker just switches from text editor to hex editor to prepare a malicious file.

[-] waltersf@bookwyr.me 1 points 4 days ago

I was never talking about vectorization, but regular file integrity. Textfiles have no error correctiveness. Yet a binary can be. Either can be edited and vectorized. Heck the point of this talk is manipulating expectations, as sha256sum isn't file verifier.

[-] lurch@sh.itjust.works 1 points 3 days ago

yeah, but nobody stops you from adding error correctiveness. you could for example just put the whole thing three times with a seperator.

however there's also an important point for text files: you can post them wherever you can write text messages. being able to digitally sign them even adds to your freedom, as you can post anonymously and your readers are able to verify it's from the same source. like you could post your heated political manifesto or cousin incest smut on 4chan or some darknet forum and if you later make a part 2, ppl will be able to tell you apart from imposters.

this post was submitted on 26 Sep 2026
28 points (96.7% liked)

cybersecurity

6482 readers
44 users here now

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Community Rules

Enjoy!

founded 3 years ago
MODERATORS