3 ms·
This is the same line of logic and statements repeated by C and C++ programmers that shortly thereafter get showed up with a list of CVEs in their 'modern C/C++
by mmstick 10y ago
This is the same line of logic and statements repeated by C and C++ programmers that shortly thereafter get showed up with a list of CVEs in their 'modern C/C++' projects. Remember the recent Curl developer PR disaster?
- flukus 10y agoI think it's too early to tell if rust will prove any better in the real world, which includes things like devs using unsafe sections to cope with time pressures.
- mmstick 10y agoUse of unsafe in Rust is not required or recommended in most, if not all situations. That said, auditing a handful of small unsafe blocks is easier than auditing an entire project.
- kbenson 10y agoThe question then is whether large chunks in unsafe is still better than the entire program in the equivalent of unsafe (C).
- Rusky 10y agoYes, it's the same line of logic because it's correct. The claim that Rust's memory safety is sound while C++'s is not is... not really the question. The question is whether that matters in practice. C++ has certainly improved in making certain mistakes easier to avoid. Now, I come down on the Rust side for many situations, but making unsubstantiated claims about your language of choice is exactly the problem people had with the Curl blog post. Please stop making them about Rust.
- mmstick 10y agoYou've living in some serious denial. You were given a point that proves that your line of thought is incorrect, and you continue on to completely ignore that point by stating that it is correct. So tell us, o'wise one, why is that top C and C++ projects are continually riddled with CVEs, crashes, and other severe issues that are 90+% the fault of C and C++? Why is it that veteran, experienced C/C++ programmers are still making these same mistakes 20, 30, and even 40 years into their careers?