3 ms·
I think this has been discussed here each time someone cites that infamous 70% statistic in a Rust thread: This is about CVEs. CVEs are about exploitable vulne
by KLAooqqP 6y ago
I think this has been discussed here each time someone cites that infamous 70% statistic in a Rust thread:
This is about CVEs. CVEs are about exploitable vulnerabilities, and most of useful software in that area is in C/C++.
In the OSS project I'm familiar with, most critical issues are not memory safety issues. Most are logic bugs.
I'm not familiar with the safety testing in Windows, which for a start does not support Valgrind or the sanitizers.
Neither am I familiar with the feature oriented culture of Chrome.
If anything, I'd be interested in the numbers of the internal ad-critical C++ code in Google or a HFT bank.
- joshuamorton 6y ago> This is about CVEs. CVEs are about exploitable vulnerabilities, and most of useful software in that area is in C/C++. I'm not sure what you're getting at here. The claim isn't that 70% of CVEs are memory vulns, but that 70% of CVEs in C/C++ are memory vulns. So how much or how little C/C++ is used is irrelevant. > If anything, I'd be interested in the numbers of the internal ad-critical C++ code in Google or a HFT bank. Do you think that Google wouldn't be pushing as hard as they are for improvements in this space if they thought things were fine and dandy?