On Jul 12, 2019, at 3:31 AM, Joe Touch <touch@xxxxxxxxxxxxxx> wrote:
This isn’t entirely true: a dangling pointer in an RFC actually becomes an attack surface if it’s important enough to search for the missing thing it once pointed to. Now I can publish an alternative piece of software that you can download that not only converts word documents to RFCs, but also sends me your personal information, etc. The real problem here is that the RFC ever pointed to a reference link that wasn’t on an IETF web site. The only time that I think this makes sense is as an informative reference. Of course, in this case in theory they are just Word templates, but can’t those contain Visual Basic? |