4 ms·
It heavily makes heavy use of parallelism and the GPU which increases the responsiveness. It's also uses Rust as a programming language instead of C++ which wil
by NiLSPACE 9y ago
It heavily makes heavy use of parallelism and the GPU which increases the responsiveness. It's also uses Rust as a programming language instead of C++ which will prevent a whole category of bugs like buffer overflows and use after free.
- braveo 9y agoAre these category of bugs a constant problem in FF?
- NiLSPACE 9y agoSome of these bugs could've been prevented with Rust: https://www.mozilla.org/en-US/security/advisories/mfsa2017-05/ https://www.mozilla.org/en-US/security/advisories/mfsa2017-0...
- wpietri 9y agoDo you have any evidence that's why users are switching away? My general belief is that general-audience users don't care at all about bugs like those. Which is why we have so very many of them, and have for decades.
- NiLSPACE 9y agoI don't, but a marketing campaign saying "using modern safe techniques" might get a little traction.
- pygy_ 9y agoRust's fearless concurrency[0] allows devs to write and refactor performant parallel code without the risk of introducing bugs, enabling them to ship upgrades faster. It's the same benefit you get from strong, static types in a large project vs one with dynamic/weak types, but for another category of bugs. In large projects, it makes a difference. --- 0. Hopefully you'll forget the meme ;-)
- MisterBastahrd 9y agoI switched away from Firefox because at the time it was bloated, buggy, and slow. I haven't switched back because I am more familiar with Google's developer tools.
- braveo 9y agoThat isn't what I asked, I asked if this class of problem is truly causing a lot of harm. Software stabilizes over time, you find problems and then you fix them. How often are these class of bugs causing catastrophic issues? That's really the important question.
- paulmlewis 9y agoThey're a big enough problem that they created Rust to deal with them.
- steveklabnik 9y agoThey're a constant problem in all browsers. Take last year's Pwn2Own for example: http://blog.trendmicro.com/pwn2own-day-2-event-wrap/ http://blog.trendmicro.com/pwn2own-day-2-event-wrap/ Demonstrated a successful code execution attack against Safari to gain root privileges using an use-after-free vulnerability in Safari and an out-of-bounds vulnerability in Mac OS X. Demonstrated a successful code execution attack against Microsoft Edge in the SYSTEM context using an uninitialized stack variable vulnerability in Microsoft Edge Demonstrated a successful code execution vulnerability against Microsoft Edge in the SYSTEM context using an out-of-bounds vulnerability in Microsoft Edge and a buffer overflow vulnerability in the Kernel. etc. Highlights mine. All of these are prevented in safe Rust.
- daddykotex 9y agoOk thanks.