3 ms·
You overestimate the number of issues that Rust would solve, versus the actual sec issues browsers have.
by jdashg 6y ago
You overestimate the number of issues that Rust would solve, versus the actual sec issues browsers have.
- steveklabnik 6y agoWhen Mozilla analyzed this, it was found that half of security issues were memory safety issues.
- atomicUpdate 6y agoYou mean Google: https://www.chromium.org/Home/chromium-security/memory-safety https://www.chromium.org/Home/chromium-security/memory-safet...
- steveklabnik 6y agoNo, that is a different statistic from the one I’m talking about. The one I’m talking about was a survey of security bugs in Firefox, including the private ones. This one (and the Microsoft one) show an even higher number! (Here’s a quick reference I found, I don’t know if pcwalton has more details https://news.ycombinator.com/item?id=12876603 https://news.ycombinator.com/item?id=12876603)
- Ar-Curunir 6y agoIt can be both (and probably is)
- Jweb_Guru 6y agoSomething like 70% of all CVEs in C++ applications (including browsers--the actual type of application doesn't seem to matter much) are memory safety issues. Yet the myth persists that memory safety isn't an important bug class for stuff written in modern C++. I think the converse is true: most C++ programmers tend to significantly underestimate the number of remaining bugs in their code that are memory safety bugs.
- edflsafoiewq 6y agoHow many memory safety issues are in the JIT? Because Rust won't help you there.
- Jweb_Guru 6y agoBugs related to the JIT are normally counted separately, AFAIK. The 70% figure tends to hold even in systems with no JIT. However, it would not surprise me if about 70% of JIT CVEs are memory safety bugs. The trend for unsafe Rust so far seems to be very similar BTW (about 70% of unsafe Rust CVEs are memory unsafety--contrasted with virtually no non-unsafe Rust CVEs that are memory unsafety, and all that were are due to compiler bugs). The overall trends tell me that in the absence of a proof assistant, however carefully you scour your code for bugs, you will miss some. And 70% of the ones you miss will be memory unsafety unless you are using a system that explicitly prevents this.
- steveklabnik 6y agoGoogle’s 70% was in C++ because it was talking about Chromium, Microsoft’s 70% was not categorized by language, and was simply “memory safety issues.”
- Jweb_Guru 6y agoThere have been a few other studies besides those two pointing to the 70% figure. It seems to be a curiously persistent figure, and I agree that it's not just about C++.