3 ms·
I wonder if languages like Rust would be helpful in areas like this? Especially considering that the strictness of the compiler might allow more "green" develo
by bionicbits 8y ago
I wonder if languages like Rust would be helpful in areas like this? Especially considering that the strictness of the compiler might allow more "green" developers opportunity to contribute.
- bsamuels 8y agoRust addresses C/C++ security issues, but that's where the security benefits end (that's still a lot of benefits though!) I really wish "units of measure" types took off in the langdev world. "String" is woefully inadequate to describe the actual type of a string; Imagine a world where string data is of type <string:urlencoded> or <string:xsssanitized>, and display functions would only accept strings of the correct type. I know F# has this, but unfortunately it never caught on elsewhere.
- archgoon 8y agoWhat are the problems with using inheritance to handle this? class urlencoded extends String; class xsssanitized extends String; then secure functions can be explicit about what type they need. void embedInPage(xssssanitized xssString);
- tptacek 8y agoMost modern frameworks, in all the mainstream languages, already have this feature, and it's usually the default. You still get XSS because you still have to override the filter to do custom HTML, but it helps a lot.
- archgoon 8y agoRight; I'm trying to understand the difference between this and the "units of measure" approach the grandparent was referencing. (To be clear, your latter point is referring to things like 'dangerouslySetInnerHTML' in react?) https://reactjs.org/docs/dom-elements.html#dangerouslysetinnerhtml https://reactjs.org/docs/dom-elements.html#dangerouslysetinn...
- spydum 8y agoI think obviously no: language definitely contributes to SOME vulnerabilities, but it does not solve all or even most of them. java apps are great example of memory safety, type safety, and still huge vulnerabilities exist in java apps.
- tptacek 8y agoNo. Rust eliminates C/C++ memory corruption vulnerabilities, but so do all the other mainstream high-level languages. What Rust enables you to do is ship software that formerly would have demanded C/C++ (kernels, drivers, embedded software, browsers, games) without having to use C/C++. That's a security win, but not a game changer for secure software development in general, the vast majority of which is done in non-C/C++ languages already.