Hacker News new | ask | show | jobs
by ewheeler 4674 days ago
i'm not convinced that the benefits outweigh the risks. wouldn't browsers have to check for malicious decompression bombs? IIRC -- even without nested zip archives -- a smallish .zip of a few files full of 0s can decompress to many gigs