4 ms·
To me, as someone that doesn't use C in their day to day life, C appears to be a security nightmare. I cannot imagine using it in a production environment that
by windsurfer 7y ago
To me, as someone that doesn't use C in their day to day life, C appears to be a security nightmare. I cannot imagine using it in a production environment that takes any amount of user input.
- carapace 7y agoYep. It's insane to use tools/languages susceptible to problems like these in 2019.
- chupa-chups 7y agoTo underscore your general point: You're totally right. But... a but: Implicit type conversions in C are cumbersome. In javascript for example, they are way more. If javascript had a similar role (i.e. bare metal code), the world would be way messier than it already is. Languages without strict type checking are in general open to problems like this, more or less depending on the leniency to check potential type error. C, being a bare-metal language is especially ugly since it allows to cast anything to anything else, granted - but is is spottable, reviewable and, for new code, you won't get away with ugly casts. In javascript you don't even see casts, they just happen. Still, javascript doesn't have an unsigned integer, so this attack vector would not work.
- tsimionescu 7y agoMore to the point, memory-safe languages cannot have these types of vulnerabilities regardless of other aspects of the type system.
- saagarjha 7y agoThat's assuming, of course, that the runtimes for those languages are correct: as numerous web browser exploits have taught us, this isn't always the case ;)
- deleted 7y ago[deleted]