Conversation
@Foxboron the attack surface of gunzip pales in comparison to the attack surface of curl/wget, bash/busybox, and the tcp stack of the underlying OS and all the sandboxing abstractions built on top of it.
1
0
1
@Foxboron Yes, but my point is that in the grand scheme of "lines of code dealing with potentially hostile code," a compression algorithm is often not the most worrisome piece.
0
0
0