4 ms·
Short answer: unlikely to end anytime soon, but likely that we start to focus on higher level bugs more than lower level issues. Long answer: If Unix and C had
by cm3 10y ago
Short answer: unlikely to end anytime soon, but likely that we start to focus on higher level bugs more than lower level issues.
Long answer: If Unix and C hadn't won the fight in the 1980s like VHS did, we wouldn't deal with such low-level bugs. It took 30 years, but we're finally getting CPUs (like lowRISC) that were inspired by BS5000 or i960 and the languages to go with it are getting mainstream. To be fair, had we as an industry taken security more seriously decades ago, we would have written critical pieces of the stack in a high-assurance Ada profile, and put microkernel design capability kernels into production. We can extend 1960s kernel designs with all kinds of features, but without a coherent design it's impossible to provide the same assurance. This is why it's great that we have L4 descendants that incorporate a capability scheme and also support a multikernel scheme (ala Barrelfish) for making better use of a cluster of cpu cores.
- sitkack 10y agoWe can't burn the world down and remake it. These things WILL happen over time, the next generations definitely are focused on safety and correctness. 1 we need to remove unsafe-machismo for the landscape, vector that energy into correctness instead of living with danger. 2, we need to figure out how to partition, segment, wrap the unsafe legacy stuff into a safe operating regime. The single biggest win is if we could load a library in another process and make cross-process calls to it.
- ygjb-dupe 10y ago> The single biggest win is if we could load a library in another process and make cross-process calls to it. What? Setting aside the fact that this can already be done in numerous different ways on many platforms, how is this a win? It's hard enough for developers to write correct code, let alone maintaining the correctness of that code while loading and executing unknown code from other parties (see web browsers, and the last 20 years of security bugs related to plugins, extensions, addons, etc).
- sitkack 10y agoThe user should be able to load 3rd party libraries in out of process sandboxes, transparently for applications which weren't written with that in mind. I am not asking for new programmer features, new end user / sys admin features in the loader.
- nixos 10y ago>we would have written critical pieces of the stack in a high-assurance Ada profile, and put microkernel design capability kernels into production You're writing on a computer magnitudes faster than the fastest computers of the 70s, with significant compiler improvement to boot. Until about 10 years ago, hand crafted Assembler was still faster than C, and the speed improvements were actually needed. This "let's write a text editor which is pretty much an advanced nano/pico in JS and have it take up 145MB" is only possible when everyone has a supercomputer in their hands anyways
- ori_b 10y ago> Until about 10 years ago, hand crafted Assembler was still faster than C, and the speed improvements were actually needed. It still is, especially when it comes to vectorization.
- nly 10y agoAnd in other areas, but that's largely because C isn't expressive enough, not because we lack the engineering know-how to compile fast vectorisation code.
- ori_b 10y agoI am not aware of a general purpose language that is expressive enough to auto vectorize generic code without basically writing in vector intrinsics.
- deleted 10y ago[deleted]