I download a file on Linux, and it has data, a filename, and some permission metadata. That’s it. It sounds like this metadata layer deserves all of the hacks that will come for it.
Most file systems have a very limited footprint of metadata. Static information. And they are usually following basic POSIX standards, to ensure that file transfers between mediums are as cross-compatible as possible.
This Alternative Data Stream is now creating this entirely new variable data stream for hackers to hide shit in. No longer can just you scan a file’s data to make sure nothing malicious is in there. Now you need complex logic to be able to both read this new stream, interpret the flags and other metadata, and take all of those different pieces of information and figure out if it’s even worth opening the damn file.
Data is data. Keep data in the data layer. Everything else is secondary, and should be kept tiny.
What the fuck is this arcane metadata bullshit?
I download a file on Linux, and it has data, a filename, and some permission metadata. That’s it. It sounds like this metadata layer deserves all of the hacks that will come for it.
deleted by creator
Most file systems have a very limited footprint of metadata. Static information. And they are usually following basic POSIX standards, to ensure that file transfers between mediums are as cross-compatible as possible.
This Alternative Data Stream is now creating this entirely new variable data stream for hackers to hide shit in. No longer can just you scan a file’s data to make sure nothing malicious is in there. Now you need complex logic to be able to both read this new stream, interpret the flags and other metadata, and take all of those different pieces of information and figure out if it’s even worth opening the damn file.
Data is data. Keep data in the data layer. Everything else is secondary, and should be kept tiny.
deleted by creator