4 ms·
I don't really understand why this doesn't cover memory safety.
by ctz 10y ago
I don't really understand why this doesn't cover memory safety.
- tyingq 10y agoOverflow, memory randomization, and other related topics are sprinkled around the document, but yes, there's not a specific section.
- naasking 10y agoSeriously. Just switching to memory safe languages would be the single biggest reduction in software vulnerabilities you could achieve with one decision.
- duneroadrunner 10y agoYes, after reading a draft[1] of this document, I suggested to them that they seemed to be insufficiently emphasizing remote execution vulnerabilities (due to invalid memory access). I also pointed out that they neglected to mention Rust and the Clang/LLVM sanitizers. (And SaferCPlusPlus[2] too.) They acknowledged my comments, but it doesn't seem to have had much effect on the document. [1] https://news.ycombinator.com/item?id=12643463 https://news.ycombinator.com/item?id=12643463 [2] shamelss plug: https://github.com/duneroadrunner/SaferCPlusPlus https://github.com/duneroadrunner/SaferCPlusPlus