3 ms·
He is talking about curl, not all software. But the claim is still BS as debunked 4 years ago by simias: https://news.ycombinator.com/item?id=13966967 https://n
by exyi 6y ago
He is talking about curl, not all software. But the claim is still BS as debunked 4 years ago by simias: https://news.ycombinator.com/item?id=13966967 https://news.ycombinator.com/item?id=13966967 7 out of 11 are pretty clearly caused by C being an unsafe language.
When I look at https://curl.se/docs/security.html https://curl.se/docs/security.html today, it does not seem to be 70%, but there is still quite a big new things called "double-free", "buffer overflow", ...
- Snetry 6y agoI can't speak for the buffer overflows since those can happen in various ways but I'd sort double frees under logic errors which he admits curl to have