3 ms·
I've spent a career of 12 years writing, reviewing and breaking C in high-security products such as HSMs. I'm still to see real world, secure C. Maybe you cou
by ctz 10y ago
I've spent a career of 12 years writing, reviewing and breaking C in high-security products such as HSMs. I'm still to see real world, secure C. Maybe you could point me towards the numerous real world examples of people getting this right. I'd prefer scaled-up outcomes here, not just saying 'djb wrote qmail'.
(Incidentally, I don't have a quarrel with C specifically. All memory-unsafe languages expand the range of terrible vulnerabilities available to the engineer. This is not defensible these days, in my view.)
> So please, pave the road and show us the safer OpenSSL-rust you have.
My contribution here is https://github.com/ctz/rustls https://github.com/ctz/rustls
- captn3m0 10y agoOff-topic, but a quick question on your project: > Kerberos >broken, obsolete, badly designed, underspecified, dangerous and/or insane Which list does Kerberos fit in?
- ctz 10y agoThere are no standard kerberos ciphersuites that use anything better than RC4/IDEA/DES/3DES: http://www.iana.org/assignments/tls-parameters/tls-parameters.xhtml#tls-parameters-4 http://www.iana.org/assignments/tls-parameters/tls-parameter.... So: broken and obsolete.
- emmelaich 10y agoRecent Windows, Linux and Java Kerberos all standardise on AES* and the ones you list are deprecated and for some have to be explicitly enabled. So .. progress is being made.
- astrodust 10y agoDJB wrote Qmail, then abandoned it like an unwanted child. He might be a good programmer, but he's a really bad maintainer. OpenSSL was all but abandoned as well. At least now there's a lot of attention being focused on making it better and more maintainable. There's numerous tire fires out there: ImageMagick, OpenSSL, some Linux kernel drivers, and other projects people just take for granted without pitching in to help fix things. Re-writing in Rust is a form of helping, and maybe in the process we'll find bugs in the originals or wholesale replace them with something better.
- andrewchambers 10y agoI think OpenBSD beg to differ. Not to mention I would argue memory exhaustion bugs like this happen in memory safe garbage collected languages frequently too.
- lambdasquirrel 10y agoThere are edge cases for everything. A language is what it makes easy.