5 ms·
> The replacement should be written in a memory-safe language. Including the TLS library. No. Memory safety is a vanishingly small subset of all bugs and secur
by otabdeveloper1 8y ago
> The replacement should be written in a memory-safe language. Including the TLS library.
No. Memory safety is a vanishingly small subset of all bugs and security problems. PHP is memory-safe, for example. Where has that gotten us?
> "There is more to life than increasing its speed."
Not if you're a computer.
- fulafel 8y agoI'm not sure if you are trolling or not. Just in case: all rce vulns in nginx have been memory safety bugs: https://www.cvedetails.com/vulnerability-list/vendor_id-10048/product_id-17956/opec-1/Nginx-Nginx.html https://www.cvedetails.com/vulnerability-list/vendor_id-1004...
- otabdeveloper1 8y agoRead what I posted again. The number of security vulnerabilities due to PHP's crappiness is two orders of magnitude greater than all of nginx vulnerabilities combined. Yet PHP is a memory-safe language. Memory safety won't fix anything by itself, it will just shuffle the shit into some other place. Now if you're claiming that if you take nginx developers and force them to use Rust they'll somehow start writing better code, then that's a valid point. Although I'm in extreme doubt that it is realistic or even true.