4 ms·
Majority of CVE's are because of C memory model, which is fixed in modern languages. C memory model is the constant source of vulnerabilities, thus it better to
by drran 5y ago
Majority of CVE's are because of C memory model, which is fixed in modern languages. C memory model is the constant source of vulnerabilities, thus it better to write new code in a memory safe language, like Rust.
- pkrumins 5y agoRust is a syntax error, not a programming language.
- DrMeepster 5y agowhat does this mean? It sounds like you tried to make a funny programming insult, but it fell flat if that's what you were going for
- moralestapia 5y ago>Majority of CVE's are because of C memory model I haven't checked that but I believe you. My only nitpick is that I wouldn't put the whole blame for that on C, as there are proper ways to produce "safer"[1] code. What other languages did was lower the entry barrier to write better code, but that doesn't mean one language is inherently better that another. 1: No code is ever safe, not even formally verified code.
- masklinn 5y ago> Majority of CVE's are because of C memory model “Memory safety” (or lack thereof) is probably less ambiguous: usually “memory model” is the interaction between program and memory, specifically as it pertains to concurrency. And in the latter understanding I believe C has about the same model as C++, which is also the one adopted by Rust. And while it’s fiddly, it’s not a complete disaster.
- phendrenad2 5y agoC and Rust have the same memory model though, unless you're using a definition of "memory model" that I'm unaware of.