4 ms·
I'm so happy to see something like this in development. Every time there's a discussion about OpenSSL vulnerabilities, the topic of a future replacement written
by Perceptes 10y ago
I'm so happy to see something like this in development. Every time there's a discussion about OpenSSL vulnerabilities, the topic of a future replacement written in Rust comes up, but no one was stepping up to the plate. Now we have some real progress towards a safer future.
- progman 10y agoThere is also Thrussh, a Rust library for SSH. Rust now begins to shine where it was designed for -- in security. According to https://doc.rust-lang.org/book/ffi.html https://doc.rust-lang.org/book/ffi.html it is possible to make callbacks from C code to Rust functions. This way other languages could take advantage of Rust's safe libraries.
- frutiger 10y agoThere have been far fewer serious vulnerabilities in OpenSSH than in OpenSSL.
- gkya 10y agoOpenSSL is not from the OpenBSD project whereas OpenSSH is.
- gkya 10y agoLanguage having safety features does not guarantee code free of vulnerabilities.
- smt88 10y agoRelated reading: https://tonyarcieri.com/would-rust-have-prevented-heartbleed-another-look https://tonyarcieri.com/would-rust-have-prevented-heartbleed...
- gkya 10y agoTed comments on this post in the article that it critiques. I do know that rust has important tools for writing secure programmes but using them is not really enforced (ie unsafe {}), thus it's possible to write exploitable bug in it. I want to note that I never used it though.
- fridsun 10y agoIn the end it's possible in any language to produce exploitable bug (apart from maybe Erlang VM?). The point is about 1) how hard (probable) it is, 2) how popular are error checking tools (C static analyzers, Google Thread Sanitizer, etc), and 3) how fast can the culprit code be found and fixed. In that regard Rust has reduced both 1) and 3) by only exposing dangerous features in unsafe {}, and greatly improved 2) since the compiler itself is checking those errors.
- Perceptes 10y agoYes, but I don't think progman was suggesting that. Rust doesn't prevent code from having logic errors, but it does protect you entirely from certain classes of errors (e.g. use-after-free memory violations) as long as you stick to safe Rust. These are some of the most common bugs in C programs which have resulted in highly publicized vulnerabilities, so Rust will take a program a very long way towards being safer than any C counterparts.