5 ms·
Out of curiosity, why is less C code a good thing?
by saji13 10y ago
Out of curiosity, why is less C code a good thing?
- pm90 10y agoMaintenance. A lot of the younger programmers have very little experience with running/working with C code and stack; they are a lot more comfortable with Java/Python/Go (for backend). So the less C code you have to deal with in your stack, the easier it is for deployment/debugging. Not to mention, the more modern languages also provide many features that allow pinpointing errors faster etc.
- pjmlp 10y agoSecurity exploits caused by memory corruption, undefined behavior, ability to inject code, numeric overflows plus whatever is common to all memory safe languages. https://www.cvedetails.com/vulnerabilities-by-types.php https://www.cvedetails.com/vulnerabilities-by-types.php
- sidlls 10y agoThere are legitimate reasons to not want to use C, but I find around here it's mainly reflexive hate and language zealotry. It's popular to hate on C (and C++) because the languages are so ubiquitous and long-used that a large body of terrible, unsecure, and poorly written code exists using them. Other languages haven't had the same success as these two yet, so haven't had their warts exposed enough to be dumped in the "automatically hated" category. Java comes close, but it also is typically lumped in the "automatically hate it" bucket and for similar reasons.
- pjmlp 10y agoIt was already clear in the late 70's and early 90's that C wasn't a reliable option to write safe systems. Dennis M. Ritchie himself on the history of the language[0] "To encourage people to pay more attention to the official language rules, to detect legal but suspicious constructions, and to help find interface mismatches undetectable with simple mechanisms for separate compilation, Steve Johnson adapted his pcc compiler to produce lint [Johnson 79b], which scanned a set of files and remarked on dubious constructions." Lint which is still mostly ignored by the masses to this day. At CppCon 2015, about 1% of the audience acknowledge using static analyzers. Per Brinch Hansen letter to C.A.R. Hoare in 1993a [1] "The 1980s will probably be remembered as the decade in which programmers took a gigantic step backwards by switching from secure Pascal-like languages to insecure C-like languages. I have no rational explanation for this trend. But it seems to me that if computer programmers cannot even agree that security is an essential requirement of any programming language, then we have not yet established a discipline of computing based on commonly accepted principles." There are many other sources of similar statements since C exists, so the hate isn't something new. Regarding C++, yes unfortunately it inherits C flaws, but at least the community tends to embrace language features to improve the language safety and push for type based programming. [0] https://www.bell-labs.com/usr/dmr/www/chist.html https://www.bell-labs.com/usr/dmr/www/chist.html [1] brinch-hansen.net/papers/1999b.pdf
- rbmiller 10y agoWhere is this mythical C++ community that promotes safe and auditable programs? Whenever I'm forced to use a C++ program it's buggier than the C equivalent.
- pjmlp 10y agoThey are here: https://isocpp.org/ https://isocpp.org/ http://cppcon.org/ http://cppcon.org/ https://github.com/isocpp/CppCoreGuidelines/blob/master/CppCoreGuidelines.md https://github.com/isocpp/CppCoreGuidelines/blob/master/CppC... http://erdani.com/index.php/books/modern-c-design/ http://erdani.com/index.php/books/modern-c-design/ https://msdn.microsoft.com/en-us/library/hh279654.aspx https://msdn.microsoft.com/en-us/library/hh279654.aspx http://stroustrup.com/Tour.html http://stroustrup.com/Tour.html http://elementsofprogramming.com/book.html http://elementsofprogramming.com/book.html Most of the C++ bugs I found happened to be written by former C developers that disregard using C++ stronger type safety, RAII, the standard library containers and usually use naked pointers alongside malloc() and free(). And that is the biggest problem with C++, its copy-paste compatibility with C, which allowed its adoption by C compiler vendors, but made it as safe as C when developers disregard best practices.
- sidlls 10y agoExcept for relatively uncomplicated, or relatively low level programs I have had the opposite experience.
- fanf2 10y agoLint is built in to modern C compilers.