Poisoning a Go Cache
lukasschwab.me
lukasschwab.me
I’m not saying that "a poisoned Go cache" should necessarily be part of everyone’s threat model, but I’d also not just dismiss it by saying "well, it requires disk access". Either might be wrong, depending on your situation.
Great article, by the way, thank you!