4 ms·
> Javascript's runtime interpretation + lack of strong typing is the real issue here and not just for embedded devices, but for any application. Explain how '
by allover 8y ago
> Javascript's runtime interpretation + lack of strong typing is the real issue here and not just for embedded devices, but for any application.
Explain how 'runtime interpretation + lack of strong typing' is significant for security.
JS is memory safe which makes it a more secure choice than e.g. C/C++.
- pjmlp 8y agoUnsanitized data given to eval() is an open door for exploits, whereas lack of strong typing makes it easier for logic programming errors, due to typos or implicit conversions. Memory corruption is just one possible attack vector.
- allover 8y agoeval() is a pretty opt-in security vuln, and there are ways of doing the equivalent in statically typed languages. Logic errors are pretty hard to quantify, but if there're stats on vulnerabilities caused by logical errors that could only happen in languages without strong types I'd love to see them. Meanwhile there's a whole class of vulnerabilities attributable to lack of memory safety that are pretty easily distinguished, including some of the most notorious (cloudbleed, heartbleed).