9 ms·
> because the open internet is damn inhospitable. And the answer to this is writing text-processing functions that you expose to the world, in C... skeptical f
by psergeant 8y ago
> because the open internet is damn inhospitable.
And the answer to this is writing text-processing functions that you expose to the world, in C... skeptical face
- simion314 8y agoMany of the high level languages/frameworks call a C library or a C kernel or a C database
- mvdwoord 8y agoYes, in ways that were learned over many years, by many people. Roll some of your own crypto, while you're at it.
- aneutron 8y agoAin't nothing wrong with that /s What could possibly go wrong
- simion314 8y agoWhat is your point? My point is that if you nodejs you still are running "unsafe" C somewhere. Also what is the point of calling out on projects that are not using "cool" languages? You don't agree with the developer choice that is OK, probably that developer does not agree with your choice and has other priorities and if is an open source project probably he wants also to have fun while coding it.
- zeth___ 8y agoThis isn't about cool this is about dangerous. C makes shooting yourself in the foot so easy and efficient it even asks for artillery support. The time and effort to secure a C program against malicious input is absolutely huge. It would be quicker to write a secure dsl that using raw C. Which brings us back to scripting languages that have that implemented already as a library you load to run your requests through.
- potta_coffee 8y agoC lovers are downvoting you but you're entirely right.
- yorwba 8y agoThe unsafe C in popular language runtimes has hopefully been written or at least reviewed by someone who knew what they were doing, and it presents a relatively controllable interface. Most people who write code in C are not that good at avoiding memory safety issues. The process is mostly to write some code, run it, then fix it until it doesn't crash immediately anymore. Have you ever been the first person to run valgrind on a codebase? Lots of uninitialized reads and use-after-free issues will be flagged, because they don't normally crash the program and therefore go undetected without using an additional checker. It can be fun to watch the error messages flow by, until you realize that now you have to file tickets for all of them. And some people won't even see the problem with those errors that don't crash the program, because potentially exploitable vulnerabilities are not as obviously bad as crashes.
- simion314 8y agoI agree, but this does not mean that some experienced developers can't have some fun creating some tools in C, they may even be less buggy and more performant then some of the other tools written in high level languages. Btw, I am not a C fan, in fact I think I have no favorite language, I use what I have to for the project
- ke29bnf 8y agoWhy did they also wrap them in new syntax and abstraction? Why not just build the ecosystem to do that and still have it all be “C”? Why not some fixes to the standard and update then old but useful code, and work on better compilers? This is what’s been confusing me for a while If you can write safe enough C for the core of an interpreted language, why not abstract that into tools and patterns that generate better, safer C and learn how to do that over the last 30 years Instead of JS and dozens of flavors, Python, ruby, lua... DRY right? My suspicion is “vanity projects generate a sense of novelty that’s easier to sell.” But if the OS and bulk of the stack are “C inside anyway” why the extra nonsense?
- legulere 8y agoMost of the string manipulation and memory management happens in the safe high level languages in such cases.
- IshKebab 8y agoYes but they have well defined and well tested places where that happens. For example you could implement a string class in C++ using strlen, strdup etc. if you were feeling insane and it would probably be fine since you only use strdup once and then all the users of you class don't have to worry about getting it wrong. If you write in C you have to use strdup every time you copy a string and there's no way you get it right 1000 times.
- tedunangst 8y agoIt's pretty hard to get strdup wrong.
- sunfish 8y agoYet, it happens: https://nvd.nist.gov/vuln/detail/CVE-2017-14064 https://nvd.nist.gov/vuln/detail/CVE-2017-14064 https://nvd.nist.gov/vuln/detail/CVE-2015-3182 https://nvd.nist.gov/vuln/detail/CVE-2015-3182 https://nvd.nist.gov/vuln/detail/CVE-2017-13748 https://nvd.nist.gov/vuln/detail/CVE-2017-13748 etc.
- tedunangst 8y agoThis is true. Although they did say "copy a string", not use strdup to copy a thing that is not a string. :)
- sunfish 8y agoYes, that's one of the three CVE's I posted ;). You got me thinking about ways one could get strdup wrong: - input is not a string -> possible UB - input is a string, but the character encoding wasn't what you thought -> possible UB - input is a string, but it was the pointer-plus-length kind -> possible UB - input is modified by another thread -> possible UB - strdup called from within a signal handler -> possible UB - failure to handle error return values -> possible UB - failure to free the memory when it's no longer needed -> memory leak - freed the memory more than once -> possible UB - used the memory after freeing it -> possible UB I've personally seen several of these in real-world code.
- zeth___ 8y agoAnd those c programs call binary files. Anyone who uses C is a hypster that just wants to use a cool language instead of of good old 1 and 0.
- skolemtotem 8y ago> And those c programs call binary files. Uh... am I missing the joke? The C programs don't "call binary files", the C programs become the binary files through compilation.
- zeth___ 8y ago>Uh... am I missing the joke? Yes, yes you are.
- kuon 8y agoWe could argue that modern static analysis tools and the compiler itself are good at catching a lot of errors, and that high level languages have bugs too. C is a dangerous beast, but with good practices it isn't that dangerous. Of course you have to be extra careful when dealing with user content, like JSON payload, but many decoders in other languages are written in C. Rust is a good solution, but it isn't trivial to learn, and might not suite all situations. I think it's great to have a C solution like this.
- zeth___ 8y agoWhen your messaging protocol is Turing complete you have no hope of a secure web server.
- peterkelly 8y agoJSON is not Turing complete
- gaius 8y agoC is a dangerous beast, but with good practices it isn't that dangerous. Of course you have to be extra careful when dealing with user content, like JSON payload, but many decoders in other languages are written in C. It isn't hard to build tools like Valgrind and AFL into your C workflow. I would take that over simply taking for granted that a higher-level language was secure just because it is interpreted. After all it's probably C under the hood anyway.
- marmaduke 8y agoThis is a good point: you can CI run tests under Valgrind with various sanitizers and -Wall -Wextra. In a small codebase with a few cores, one can compile and run a test suite faster than it takes for a Django app to start.
- unrealhoang 8y agoI don’t think any non-gc language is trivial to learn, C also. Manual memory management is hard, and either you learn from the system (C way) or learn it upfront from the language (Rust way), it’s still the same amount of concept you have to digest to write practical software.
- yani 8y agoIt says hipster-free which will imply to me that it is not for the typical startup developer
- jeremyjh 8y agoIs there anyone other than hipsters consciously trying to avoid being a hipster?
- 1_player 8y agoExactly. Who would code a web app in 2018 in C? That's right, hipsters. Seasoned developers would use a tool more fit for the job, like Java, Python or even PHP. Seasoned hipsters would use Node, Clojure or Elixir.
- chris_wot 8y agoNormally I would consider this to be an unhelpful comment, but actually in this case, you're right.
- potta_coffee 8y agoI'm 95% that the whole thing is an elaborate joke.