5 ms·
Even though you can still screw up as as a programmer in a better tool, you should still pick that tool if that reduces the security risk by a number of percent
by fetbaffe 8y ago
Even though you can still screw up as as a programmer in a better tool, you should still pick that tool if that reduces the security risk by a number of percent over another tool. (as a swede would say "Think of the percentage")
So why doesn't everyone go with the better tool? Large problem is that experienced programmers encourages new programmers to use the older & less secure tools. I guess in a way to stay relevant.
Just this past week it has been an article about C programming almost everyday on the top list here at Hacker News.
- nineteen999 8y ago> Even though you can still screw up as as a programmer in a better tool, you should still pick that tool if that reduces the security risk by a number of percent over another tool. I agree in general, but not necessarily if the "better tool" doesn't run on or generate code for your target platform, or doesn't meet your performance requirements, or memory constraints, or the requirements to interface with other languages via a common ABI etc, etc etc. And, in those situations, you need to BE CAREFUL. > Large problem is that experienced programmers encourages new programmers to use the older & less secure tools. I guess in a way to stay relevant. Oh I get it. Blame the older generation who wrote the platforms & tools that gave you a job in the first place. If that doesn't work, blame the tools. Blame anything but yourself for writing shit code. I see.
- fetbaffe 8y agoSure, there is always practical limitations, but I think that is less of a problem today than it used to be. We have newer languages, but also a lots of languages have gotten better to interface lower level libraries. Experienced programmers can be a huge asset, but at the same time a curse, there is no contradiction there. And I'm not arguing for a revolution to throw out all of what has been gained in software, I just say that new projects should to leave the old tools behind. I am of course also guilty for proselytizing bad ideas & writing bad code.
- tveita 8y ago> Blame the older generation who wrote the platforms & tools that gave you a job in the first place. Sure, why not. Almost all of them write "shit code", by your definition. https://www.cvedetails.com/vulnerability-list/vendor_id-72/product_id-767/GNU-Glibc.html https://www.cvedetails.com/vulnerability-list/vendor_id-72/p... https://www.cvedetails.com/vulnerability-list/vendor_id-33/product_id-47/Linux-Linux-Kernel.html https://www.cvedetails.com/vulnerability-list/vendor_id-33/p... https://www.cvedetails.com/vulnerability-list/vendor_id-97/product_id-163/Openbsd-Openbsd.html https://www.cvedetails.com/vulnerability-list/vendor_id-97/p... Plenty of people claim they can write secure C code, and 99% of them are rookies that have learned the rules but not their own limitations, IMO.