(no title)
sigstoat | 2 years ago
> Yep, that's exactly it. Your TLS certificate is not sent as string, and neither are your TCP packets, nor the images contained in them.
...all of those things mentioned have defined serialization. i expect all of them have had security issues because of problems with deserialization code.
BoppreH|2 years ago
What is your point? That strings don't need defined formats? That they have less security issues?