4 ms·
I know it's trendy to hate on C but most security bugs are not memory access related errors. Most are logic errors which any language is susceptible to.
by zik 8y ago
I know it's trendy to hate on C but most security bugs are not memory access related errors. Most are logic errors which any language is susceptible to.
- pjmlp 8y agoTell that to Google, which presented a report at Linux Kernel Summit 2018, where 68% from Linux kernel CVEs are caused by C's memory corruption features, and has been pushing for the Kernel Self Preservation Project on Linux. The videos are freely available. As for hating C's lack of safety features, it goes back to the earlier 80's from Algol/Pascal/Modula-2/Ada side. So no, it isn't something new, just now the always on Internet and IoT adoption are making it relatively easier to prove our point.
- SEJeff 8y agoI think KSP is Kernel Self Protection and Kees Cook has been pushing it since he was the kernel security guy @ Canonical many years ago: https://kernsec.org/wiki/index.php/Kernel_Self_Protection_Project https://kernsec.org/wiki/index.php/Kernel_Self_Protection_Pr...
- pjmlp 8y agoYeah I get it wrong all the time, thanks for the correction. I only became aware of his work since Google.
- SEJeff 8y agoAll good! He was at Canonical for awhile actually, but did a lot on proactive security and I’ve followed him since. The “SE” in my username is a hat tip to SELinux, as I’ve always been a fan of the Flask Security Architecture. https://wiki.ubuntu.com/KeesCook https://wiki.ubuntu.com/KeesCook
- naniwaduni 8y agoIn practice, the key to avoiding logic errors tends to be well-considered interface design. Not all languages are necessarily equally susceptible to logic errors, though, and C is rather middling in that regard.