3 ms·
Ugh... these kinds of extreme posts really piss me off. Yes, C is unsafe. Yes, there are safer higher level languages, but there's a reason C is used. Because i
by charlesL 11y ago
Ugh... these kinds of extreme posts really piss me off. Yes, C is unsafe. Yes, there are safer higher level languages, but there's a reason C is used. Because it's REALLY freaking fast, and allows you to actually tune how memory is used.
The issue with C is not the language itself. It's the complexity of the project. Once a project reaches a certain size, no programmer will be able to keep the entire thing in their head at one time. That's why the bugs appear.
I have no issue with saying that C is hard to work with in giant projects. If you have an issue with that, write the sections of code that bottleneck in C, and then glue them together with a higher level language (I personally like Lua for this).
Also, the post is mainly complaining about security issues for Chrome. Assuming Chrome is rewritten in Rust or Go, will these security issues vanish? Of course not. Bugs (especially security bugs) will exist in all software, whether it's written in C or Ruby.
So the results of rewriting all C code in the world is: slower, less optimized code and continued existence of security bugs. Sounds great.
- steveklabnik 11y ago> Assuming Chrome is rewritten in Rust or Go, will these security > issues vanish? Of course not It's true that they will never _vanish_, but all of the ones related to memory safety, which are the ones the article focuses on, shouldn't happen in Rust: > 70% of the high-risk bugs in Chrome 44 would have been prevented > if Chrome were written in a memory-safe language instead of C/C++. (it's true that it's not 100%, because someone could still write bad code in an unsafe block, but that's a _significant_ reduction in the surface area, which should lead to a similar reduction in errors.)
- pjmlp 11y ago> So the results of rewriting all C code in the world is: slower, less optimized code and continued existence of security bugs. Sounds great. C compilers are fast today. They used to be crap in the early 90's and seen as we see Python and Ruby performance nowadays. Execution speed isn't a magic feature of C, not available to any other compiled language. C is the systems programming language that allows for buffer overruns, memory corruption and dangling pointers everywhere in the codebase. Other systems programming languages allow developers to explicitly only use those features explicitly when required. In C using strings is enough.