5 ms·
Can I ask you why? I mean, I know about memory safety and stuff, but it is that bad?
by 0xFFFFFFFFF 5y ago
Can I ask you why? I mean, I know about memory safety and stuff, but it is that bad?
- roca 5y agoYes it is.
- deleted 5y ago[deleted]
- pizza234 5y agoIndependent researches (Microsoft/Mozilla) showed that around 70% of security vulnerabilities are caused by memory safety bugs. That's one heck of a "memory safety and stuff" :) Here's one reference: https://msrc-blog.microsoft.com/2019/07/18/we-need-a-safer-systems-programming-language/ https://msrc-blog.microsoft.com/2019/07/18/we-need-a-safer-s...
- postalrat 5y ago"memory safety bugs" sounds pretty broad. What sort of vulnerability doesn't involve memory access?
- shatteredspace 5y agoThat reference and the original blog post where 70% was indicated is only dealing with security vulnerabilities in Microsoft's software, not everyone's. So while other software that isn't Microsoft most certainly has memory safety bugs, this blog doesn't speak for those, only Microsoft's. The only part that Mozilla is indicated is in reference to Rust.
- syvolt 5y agoIf one of the largest software companies around can't get memory safety right, it does make a guy start to think that maybe most people should avoid having to handle it if they can.
- shatteredspace 5y agoI don't have a fully developed opinion on that, so I won't try to come up with one on the spot. My comment is purely because I felt the parent left out details about the blog post that should have been pointed out.
- saagarjha 5y agoGoogle has done similar research on their codebases and found results in line with Microsoft’s.