8 ms·
C is a systems language from the ground up with decades of successful use and knowledge behind it. Rust is the new kid on the block with everything to prove. C
by deepfriedtech 11y ago
C is a systems language from the ground up with decades of successful use and knowledge behind it. Rust is the new kid on the block with everything to prove. C is the best tool for the job. I think Theo de Raadt and his devs know exactly what they are doing. With only two holes in the default install in over a decade, why fix what isn't broken?
I'm one of these guys that still clings to old tech because it works. If C works, use it. Rust is too new, too unproven. C has proven its worth with billions of lines of code, something Rust will likely never achieve as a niche language.
- nickpsecurity 11y ago"C is a systems language from the ground up" It was actually an extension of BCPL, which wasn't designed: just what parts of a good language compiled on 1960's hardware. Proof below. http://pastebin.com/UAQaWuWG http://pastebin.com/UAQaWuWG "with decades of successful use" It actually had decades of failures with all sorts of bugs and hacks that safer, system languages dodged by design. Only the best coders got successful and secure use out of it. We praise OpenBSD quality for a reason: it's not easy. "Rust is the new kid on the block with everything to prove. " This is true. I have a rule against using anything new for security-critical coding if its in the TCB. Takes time to discover all the issues in things. "With only two holes in the default install in over a decade" Propaganda I've called out plenty. On the other systems, people finding bugs often weaponize them, declare a vulnerbaility, and add that to the count. OpenBSD treats bugs as just bugs then fixes them while assuming their mitigations stopped any attack attempts. It's easy to say you only had 2 vulnerabilities when you're not counting vulnerabilities. ;) "C has proven its worth with billions of lines of code, something Rust will likely never achieve as a niche language." It does have proven worth. After billions of lines, you can be sure you'll be fixing all sorts of things and doing breach notifications if you rely on it. Unless you pay extra money for top coders. Rust already beat it on app-level safety w/ effects of low-level interactions and compiler risk being next to assess or address. Ada and SPARK beat both for systematic safety with many empirical results from case studies and field use. Safe versions of C like Cyclone and Popcorn outdid C, too, in security but nobody invested more in them. TAL and CoqASM are even doing safety/security at assembler level. And so we have a language proven worthless for quality or security the mainstay of quality or security focused UNIXen even with decades of alternatives empirically shown to be better. Sounds like a cultural thing to me. Drawback too. Only advantages: lots of people know it and lots of existing code/tooling. Valid reasons to choose it for existing BSD code but allows it was inferior on other angles. And that rewrites to safer languages for it or new projects should be ongoing.
- fredmorcos 11y agoI am genuinely wondering, what is (or could you point me to) the alternative with the following properties: - Compiled, type-safe and available for armv6. - Simple semantics: Rust and Ada are complex (C++-ish) and it gets hard to limit the number of memory allocations/accesses as well as data copies going on. - Tooling and discoverability: Man pages and Emacs with a few modes that are easy to setup beats anything I've tried so far. I understand that C has shortcomings when it comes to safety/security and even lacks features that would make programming certain things easier, but what do you suggest I use when I want to write a UNIX daemon that needs to transfer a boatload of data from disk over the network and vice-versa? I personally like it, I find it to be clear and concise, a little tedious but at the price of giving me fine grained control over the data in memory: I just have to be careful with that.
- nickpsecurity 11y agoThe problem is, outside Ada and Rust, there isn't much of anything that's maintained because people stayed rejecting anything but C. I will post this on Ada so you can see (a) a nice survey of problems that show up and (b) how it systematically counters them. http://www.adacore.com/uploads/technical-papers/SafeSecureAdav2015-covered.pdf http://www.adacore.com/uploads/technical-papers/SafeSecureAd... The best candidates for simpler ones were Wirth-like languages, esp Modula-3. I used to recommend Delphi as it was a Pascal alternative to Visual C++ whose apps rarely crashed. Free Pascal succeed w/ Lazaurus IDE succeeded it w/ tons of hardware support. Component Pascal w/ Blackbox is still active AFAIK. D is quite active. Some Modula-2 benefits https://news.ycombinator.com/item?id=9640126 https://news.ycombinator.com/item?id=9640126 Modula-3 features https://en.wikipedia.org/wiki/Modula-3 https://en.wikipedia.org/wiki/Modula-3 Note: Fast to compile, fast to run, easy to read, easy to integrate, optional GC, optional OOP... why we need C and C++ again? Outside legacy systems... Free Pascal http://www.freepascal.org/ http://www.freepascal.org/ Component Pascal https://en.wikipedia.org/wiki/Component_Pascal https://en.wikipedia.org/wiki/Component_Pascal D language (C/C++ successor) https://en.wikipedia.org/wiki/D_%28programming_language%29 https://en.wikipedia.org/wiki/D_%28programming_language%29 Julia http://julialang.org/ http://julialang.org/ Note: It's a language for scientific programming but it's worth considering given speed and C support. On functional side, people are writing OS's in Haskell, Ocaml, and so on. OcaPic put Ocaml on 8-bitters. ATS Language was used for drivers and 8-bitters. RED/System is like LISP w/out parenthesis for system programming with ability to make DSL's. Any such language can have safety checks built in or output something for analysis. So, even functional languages are performing acceptably in places where C used to be required. Just need more people investing into any trouble spots. Someone could also pick up the code of Popcorn, Cyclone, or another safer C to develop it. Cyclone is worth linking to as it was so clever: https://en.wikipedia.org/wiki/Cyclone_%28programming_language%29 https://en.wikipedia.org/wiki/Cyclone_%28programming_languag... Just gotta maintain the front-end. Ivory language from Galois is still maintained & extracts to C. Tools like Softbound+CETS will autotransform your code to safety at a 10-40% performance hit. A typed assembler language like TALx86 or custom one from Hyde's HLA would give you lower level than C with more safety ironically. So, many options for OSS to build on with some like Pascals having mature tooling. EDIT: Just remembered the Pike programming language used in Roxen web & app servers as a C alternative. They're FAST. So, do google it.